CVE-2018-9071
5.3
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information related to the current authentication configuration settings. Exposed settings relate to password lengths, expiration, and lockout configuration.
Affected (1)
Products: Lenovo: Chassis Management Module Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0.0 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Chassis Management Module | All versions |
References (2)
Source: psirt@lenovo.com
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Timeline
No history available yet.