← Back

CVE-2018-9071

nvd nist
Published: Nov 16, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information related to the current authentication configuration settings. Exposed settings relate to password lengths, expiration, and lockout configuration.

Affected (1)

1 product
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.0.0
Running on/withPlatform Versions
Lenovo
Chassis Management Module
All versions

References (2)

Source: psirt@lenovo.com
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory

Timeline

No history available yet.