IPMI Cipher Suite Zero Authentication Bypass
Critical Nessus Plugin ID 68931
SynopsisThe remote IPMI service is affected by an authentication bypass.
DescriptionThe IPMI service listening on the remote system has cipher suite zero enabled, which permits logon as an administrator without requiring a password. Once logged in, a remote attacker may perform a variety of actions, including powering off the remote system.
Note that this plugin checks generically for the Cipher Suite Zero authentication bypass vulnerability using a number of common accounts.
SolutionDisable cipher suite zero or limit access to the IPMI service.