Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-4856

Опубликовано: 20 дек. 2012
Источник: nvd
CVSS2: 7.9
EPSS Низкий

Описание

The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remote attackers to execute arbitrary code via unspecified vectors.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:o:ibm:power_5_system_firmware:*:*:*:*:*:*:*:*
Версия до sf240_418 (включая)
cpe:2.3:o:ibm:power_5_system_firmware:sf240_201_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_202_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_219_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_222_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_233_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_258_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_259_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_261_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_284_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_298_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_299_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_320_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_332_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_338_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_358_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_371:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_382_382:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_403_382:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_415_382:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_417:*:*:*:*:*:*:*

Одно из

cpe:2.3:h:ibm:power_5:9110-51a:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9110-510:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9111-285:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9111-520:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9113-550:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9115-505:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9116-561:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9117-570:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9118-575:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9123-710:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9124-720:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9131-52a:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9133-55a:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9405-520:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9406-520:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9406-525:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9406-550:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9406-570:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9407-515:*:*:*:*:*:*:*

EPSS

Процентиль: 67%
0.00543
Низкий

7.9 High

CVSS2

Дефекты

CWE-255

Связанные уязвимости

github
около 3 лет назад

The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remote attackers to execute arbitrary code via unspecified vectors.

EPSS

Процентиль: 67%
0.00543
Низкий

7.9 High

CVSS2

Дефекты

CWE-255