CVE-2018-9084
Estado: ModificadaMedia (6.5)—
In System Management Module (SMM) versions prior to 1.06, if an attacker manages to log in to the device OS, the validation of software updates can be circumvented.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.73%
- Percentil entre todas las CVEs puntuadas: 53
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-9084",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "psirt@lenovo.com",
"affectedData": [
{
"vendor": "Lenovo",
"product": "ThinkSystem SMM",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "1.06",
"versionType": "custom"
}
]
}
]
}
],
"published": "2018-11-27T14:29:00.713",
"references": [
{
"url": "https://support.lenovo.com/us/en/solutions/LEN-24374",
"tags": [
"Vendor Advisory"
],
"source": "psirt@lenovo.com"
},
{
"url": "https://support.lenovo.com/us/en/solutions/LEN-24374",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In System Management Module (SMM) versions prior to 1.06, if an attacker manages to log in to the device OS, the validation of software updates can be circumvented."
},
{
"lang": "es",
"value": "En System Management Module (SMM), en versiones anteriores a la 1.06, si un atacante consigue iniciar sesión en el sistema operativo del dispositivo, la validación de las actualizaciones de software puede omitirse."
}
],
"lastModified": "2026-06-17T02:06:03.463",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:lenovo:system_management_module_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9FD0EA83-B8E2-4C91-B32C-A8ED8A966974",
"versionEndExcluding": "1.06"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:lenovo:thinkagile_hx_enclosure_7x81:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7CC0357A-E355-43CF-A3A0-FDBAC9579E24"
},
{
"criteria": "cpe:2.3:h:lenovo:thinkagile_hx_enclosure_7y87:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "97F59C97-615C-47A8-BA90-B1C70A10A0A9"
},
{
"criteria": "cpe:2.3:h:lenovo:thinkagile_hx_enclosure_7z02:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "84A63456-58CF-4640-97DE-C61A37036FFD"
},
{
"criteria": "cpe:2.3:h:lenovo:thinkagile_vx_enclosure_7y11:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7E6AB649-A907-4B4D-A0F6-7E09619F6575"
},
{
"criteria": "cpe:2.3:h:lenovo:thinkagile_vx_enclosure_7y91:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "42A3257B-59D0-44D5-8B18-AABE9469F8F7"
},
{
"criteria": "cpe:2.3:h:lenovo:thinksystem_d2_enclosure_7x20:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "52EF5FF3-6312-4C6A-A09E-1921D039D626"
},
{
"criteria": "cpe:2.3:h:lenovo:thinksystem_modular_enclosure_7x22:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E0FCCCB3-91FB-4EB8-8087-2E686EDBA78F"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@lenovo.com"
}