CVE-2018-9084
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
In System Management Module (SMM) versions prior to 1.06, if an attacker manages to log in to the device OS, the validation of software updates can be circumvented.
Affected (1)
Products: Lenovo: System Management Module Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.06 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkagile Hx Enclosure 7x81 | All versions |
Lenovo Thinkagile Hx Enclosure 7y87 | All versions |
Lenovo Thinkagile Hx Enclosure 7z02 | All versions |
Lenovo Thinkagile Vx Enclosure 7y11 | All versions |
Lenovo Thinkagile Vx Enclosure 7y91 | All versions |
Lenovo Thinksystem D2 Enclosure 7x20 | All versions |
Lenovo Thinksystem Modular Enclosure 7x22 | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.