Skip to content

H3-2020-0017

IPMI Cipher Zero Vulnerability

Category VULNERABILITY
Base Score 7.5

Description

Various vendor IPMI implementations allow remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.

Impact

An attacker exploiting the Cipher Zero vulnerability may gain control of the management interface of a system. This level of access potentially allows an attacker to control hardware or software at the system level.

References