CVE-2018-16089
Estado: ModificadaAlta (7.5)—
In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.74%
- Percentil entre todas las CVEs puntuadas: 77
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-78
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-16089",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 8.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.6
}
]
},
"affected": [
{
"source": "psirt@lenovo.com",
"affectedData": [
{
"vendor": "Lenovo",
"product": "ThinkSystem SMM",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "1.06",
"versionType": "custom"
}
]
}
]
}
],
"published": "2018-11-27T14:29:00.323",
"references": [
{
"url": "https://support.lenovo.com/us/en/solutions/LEN-24374",
"tags": [
"Vendor Advisory"
],
"source": "psirt@lenovo.com"
},
{
"url": "https://support.lenovo.com/us/en/solutions/LEN-24374",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user."
},
{
"lang": "es",
"value": "En System Management Module (SMM), en versiones anteriores a la 1.06, un campo en la cabecera de las imágenes de actualización del firmware de SMM no está lo suficientemente saneado, lo que permite una inyección de comandos tras la autenticación en el SMM como el usuario root."
}
],
"lastModified": "2026-06-17T01:43:42.273",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:lenovo:system_management_module_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9FD0EA83-B8E2-4C91-B32C-A8ED8A966974",
"versionEndExcluding": "1.06"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:lenovo:thinkagile_hx_enclosure_7x81:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7CC0357A-E355-43CF-A3A0-FDBAC9579E24"
},
{
"criteria": "cpe:2.3:h:lenovo:thinkagile_hx_enclosure_7y87:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "97F59C97-615C-47A8-BA90-B1C70A10A0A9"
},
{
"criteria": "cpe:2.3:h:lenovo:thinkagile_hx_enclosure_7z02:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "84A63456-58CF-4640-97DE-C61A37036FFD"
},
{
"criteria": "cpe:2.3:h:lenovo:thinkagile_vx_enclosure_7y11:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7E6AB649-A907-4B4D-A0F6-7E09619F6575"
},
{
"criteria": "cpe:2.3:h:lenovo:thinkagile_vx_enclosure_7y91:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "42A3257B-59D0-44D5-8B18-AABE9469F8F7"
},
{
"criteria": "cpe:2.3:h:lenovo:thinksystem_d2_enclosure_7x20:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "52EF5FF3-6312-4C6A-A09E-1921D039D626"
},
{
"criteria": "cpe:2.3:h:lenovo:thinksystem_modular_enclosure_7x22:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E0FCCCB3-91FB-4EB8-8087-2E686EDBA78F"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@lenovo.com"
}