« Volver al listado

CVE-2018-9083

Estado: ModificadaAlta (8.1)—

In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-9083",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@lenovo.com",
      "affectedData": [
        {
          "vendor": "Lenovo",
          "product": "ThinkSystem SMM",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "1.06",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-11-27T14:29:00.667",
  "references": [
    {
      "url": "https://support.lenovo.com/us/en/solutions/LEN-24374",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@lenovo.com"
    },
    {
      "url": "https://support.lenovo.com/us/en/solutions/LEN-24374",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability."
    },
    {
      "lang": "es",
      "value": "System Management Module (SMM) en versiones anteriores a la 1.06 contiene credenciales root por defecto, lo que puede emplearse para iniciar sesión en el sistema operativo del dispositivo (si el atacante consigue habilitar conexiones SSH o Telnet mediante otras vulnerabilidades)."
    }
  ],
  "lastModified": "2026-06-17T02:06:03.267",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lenovo:system_management_module_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9FD0EA83-B8E2-4C91-B32C-A8ED8A966974",
              "versionEndExcluding": "1.06"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lenovo:thinkagile_hx_enclosure_7x81:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "7CC0357A-E355-43CF-A3A0-FDBAC9579E24"
            },
            {
              "criteria": "cpe:2.3:h:lenovo:thinkagile_hx_enclosure_7y87:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "97F59C97-615C-47A8-BA90-B1C70A10A0A9"
            },
            {
              "criteria": "cpe:2.3:h:lenovo:thinkagile_hx_enclosure_7z02:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "84A63456-58CF-4640-97DE-C61A37036FFD"
            },
            {
              "criteria": "cpe:2.3:h:lenovo:thinkagile_vx_enclosure_7y11:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "7E6AB649-A907-4B4D-A0F6-7E09619F6575"
            },
            {
              "criteria": "cpe:2.3:h:lenovo:thinkagile_vx_enclosure_7y91:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "42A3257B-59D0-44D5-8B18-AABE9469F8F7"
            },
            {
              "criteria": "cpe:2.3:h:lenovo:thinksystem_d2_enclosure_7x20:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "52EF5FF3-6312-4C6A-A09E-1921D039D626"
            },
            {
              "criteria": "cpe:2.3:h:lenovo:thinksystem_modular_enclosure_7x22:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E0FCCCB3-91FB-4EB8-8087-2E686EDBA78F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@lenovo.com"
}