Question
We run Nessus security scans and have questions on two issues that come up.

IPMI v2.0 Password Hash Disclosure.

IPMI service is affected by an authentication bypass.

We use system: Supermicro X9DBS-F

Can you tell me if these vulnerabilities are fixed in a particular version of IPMI?
Print
Answer
It should be fixed already, please see our CVE Update document

www.supermicro.com/products/nfo/files/IPMI/CVE_Update.pdf


For IPMI v2.0 Password Hash Disclosure – that is CVE-2013-4786, our document showed it is fixed in X9 firmware 3.19 and above.

IPMI service is affected by an authentication bypass. – That is CVE-2013-4782, CVE-2013-4783, CVE-2013-4784, CVE-2014-2955. That is addressed in the document also, at this link
http://www.supermicro.com/support/faqs/faq.cfm?faq=16536
Was this FAQ helpful?
Enter Comments Below:
Note: Your comments/feedback should be limited to this FAQ only. For technical support, please send an email to .
Enter your email address below if you'd like technical support staff to reply:
Please type the Captcha (no space)
K T U G
Find more questions
Still Need Support?
Having trouble finding what you're searching for? Contact our support team for further assistance.

Certain products may not be available in your region