cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6804
Views
0
Helpful
6
Replies

IPMI v2.0 password hash disclosure Vulnerability

mkhriesa
Level 1
Level 1

we have IPMI v2.0 password hash disclosure Vulnerability on the UCS where we installed the cucm 10.5

I see from the solution is to disable the IPMI  , could you please advise how and provide more details for the solution of this bug

6 Replies 6

Gregory Brunn
Spotlight
Spotlight

Is this being shown as the result of a security scan, can you shut down your cimc management interface run the scan again?  This is of course your cimc is utilizing the dedicated m port and not shared LoM port.

 

 

Gregory Brunn
Spotlight
Spotlight

Is this being shown as the result of a security scan, can you shut down your cimc management interface run the scan again?  This is of course your cimc is utilizing the dedicated m port and not shared LoM port

 

Yes its a security scan, if its from cimc how we can solve it?

You can disable the Cimc.

Also you can update bios and cimc to see if that solves it would need to do more research on if the update would fix it.

https://www.cisco.com/c/en/us/about/security-center/ipmi-vulnerabilities.html

I would read this and disable tech support and ensure IPMI over lan is disabled.

Is there any affect if we disable it?