CVE-2015-0137: IBM Powervc

Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.

IBM PowerVC Standard 1.2.0.x before 1.2.0.4 and 1.2.1.x before 1.2.2 validates Hardware Management Console (HMC) certificates only during the pre-login stage, which allows man-in-the-middle attackers to spoof devices via a crafted certificate.

Affected products

  • IBM Powervc: version 1.2.0.0 only; version 1.2.0.1 only; version 1.2.0.2 only; version 1.2.0.3 only; version 1.2.1.0 only; version 1.2.1.1 only

Published 2015-03-24. Last modified 2026-06-17.