Lenovo
Lenovo System Management Module Firmware: vulnerabilidades y CVE
Lenovo System Management Module Firmware tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-9084 | Media (6.5) | 0.73% | — | 27 nov 2018 | In System Management Module (SMM) versions prior to 1.06, if an attacker manages to log in to the device OS, the validation of software updates can be circumvented. |
| CVE-2018-9083 | Alta (8.1) | 1.1% | — | 27 nov 2018 | In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via… |
| CVE-2018-16096 | Media (6.1) | 0.65% | — | 27 nov 2018 | In System Management Module (SMM) versions prior to 1.06, the SMM web interface for changing Enclosure VPD fails to sufficiently sanitize all input for HTML tags, possibly opening a path for cross-site scripting. |
| CVE-2018-16095 | Media (5.9) | 0.92% | — | 27 nov 2018 | In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a debug log when user authentication fails. |
| CVE-2018-16094 | Alta (8.1) | 0.89% | — | 27 nov 2018 | In System Management Module (SMM) versions prior to 1.06, an internal SMM function that retrieves configuration settings is prone to a buffer overflow. |
| CVE-2018-16092 | Alta (8.1) | 0.87% | — | 27 nov 2018 | In System Management Module (SMM) versions prior to 1.06, the FFDC feature includes the collection of SMM system files containing sensitive information; notably, the SMM user account credentials and the system shadow… |
| CVE-2018-16091 | Alta (8.1) | 0.57% | — | 27 nov 2018 | In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to several buffer overflows. |
| CVE-2018-16090 | Alta (7.5) | 0.87% | — | 27 nov 2018 | In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to post-authentication command injection. |
| CVE-2018-16089 | Alta (7.5) | 1.7% | — | 27 nov 2018 | In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user. |
Otros productos de Lenovo
Xclarity Administrator · 28Thinkcentre M625q Firmware · 28Thinkcentre M75n Firmware · 27Ideacentre G5-14imb05 Firmware · 27V50t-13imb Firmware · 27Ideacentre 5-14iob6 Firmware · 27Ideacentre Gaming 5-14iob6 Firmware · 27Thinkcentre M75t GEN 2 Firmware · 26V30a-22iml Firmware · 26Ideacentre 3-07imb05 Firmware · 26Ideacentre Creator 5-14iob6 Firmware · 26Ideacentre C5-14imb05 Firmware · 26