CVEs (9)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Lenovo 1System Management Module Firmware Nov 21, 2024 Nov 27, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In System Management Module (SMM) versions prior to 1.06, if an attacker manages to log in to the device OS, the validation of software updates can be circumvented. |
1Lenovo 1System Management Module Firmware Nov 21, 2024 Nov 27, 2018 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via s...Show more |
1Lenovo 1System Management Module Firmware Nov 21, 2024 Nov 27, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In System Management Module (SMM) versions prior to 1.06, the SMM web interface for changing Enclosure VPD fails to sufficiently sanitize all input for HTML tags, possibly opening a path for cross-site scripting. |
1Lenovo 1System Management Module Firmware Nov 21, 2024 Nov 27, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a debug log when user authentication fails. |
1Lenovo 1System Management Module Firmware Nov 21, 2024 Nov 27, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In System Management Module (SMM) versions prior to 1.06, an internal SMM function that retrieves configuration settings is prone to a buffer overflow. |
1Lenovo 1System Management Module Firmware Nov 21, 2024 Nov 27, 2018 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 In System Management Module (SMM) versions prior to 1.06, the FFDC feature includes the collection of SMM system files containing sensitive information; notably, the SMM user account credentials and the system shadow fil...Show more |
1Lenovo 1System Management Module Firmware Nov 21, 2024 Nov 27, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to several buffer overflows. |
1Lenovo 1System Management Module Firmware Nov 21, 2024 Nov 27, 2018 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to post-authentication command injection. |
1Lenovo 1System Management Module Firmware Nov 21, 2024 Nov 27, 2018 N/A· v4 7.5 HIGH· v3 8.5 HIGH· v2 In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user. |