← Back

CVE-2018-9083

nvd nist
Published: Nov 27, 2018Modified: Nov 21, 2024

JSON object

Loading...
8.1
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.

Affected (1)

1 product
System Management Module Firmware
Configuration A
1 vulnerable · 7 platform
Vulnerable SoftwareAffected Versions
Before 1.06
Running on/withPlatform Versions
Lenovo
Thinkagile Hx Enclosure 7x81
All versions
Lenovo
Thinkagile Hx Enclosure 7y87
All versions
Lenovo
Thinkagile Hx Enclosure 7z02
All versions
Lenovo
Thinkagile Vx Enclosure 7y11
All versions
Lenovo
Thinkagile Vx Enclosure 7y91
All versions
Lenovo
Thinksystem D2 Enclosure 7x20
All versions
Lenovo
Thinksystem Modular Enclosure 7x22
All versions

References (2)

Source: psirt@lenovo.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.