Raritan PX before 1.5.11 on DPXR20A-16 devices allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.
References
Link Resource
http://seclists.org/fulldisclosure/2014/Jul/14
http://www.kb.cert.org/vuls/id/712660 Third Party Advisory US Government Resource
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: certcc

Published: 2014-07-14T21:00:00

Updated: 2014-07-14T20:57:01

Reserved: 2014-04-21T00:00:00


Link: CVE-2014-2955

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2014-07-14T21:55:05.750

Modified: 2014-07-15T16:24:44.630


Link: CVE-2014-2955

JSON object: View

cve-icon Redhat Information

No data.

CWE