Boletines de Vulnerabilidades

Security Bulletin: TPM on the Integrated Management Module II (IMM2) of Flex System x222 compute node is not configured correctly (CVE-2014-0881)


Información sobre el sistema

   
Software afectado IBM

Descripción

The IMM2 TPM on the Flex System x222 compute node is not configured correctly which can be exploited to steal keys or to perform denial of service type attacks. CVE(s): CVE-2014-0881 Affected product(s) and affected version(s): Flex System x222 compute node Firmware 1.00 to 3.56 (1AOO10I to 1AOO50K) Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin: https://www-947.ibm.com/support/entry/myportal/docdisplay?lndocid=MIGR-5094725

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_tpm_on_the_integrated_management_module_ii_imm2_of_flex_system_x222_compute_node_is_not_configured_correctly_cve_2014_0881?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2014-0881 and CVE-2014-0882.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-03-04

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT