Description
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets.
No analysis available yet.
Remediation
Vendor Solution
Update to CMM v 2.0.0 or higher
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-20676 | Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets. |
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/solutions/LEN-23806 |
|
History
No history.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-05T07:17:50.603Z
Reserved: 2018-03-27T00:00:00.000Z
Link: CVE-2018-9073
No data.
Status : Modified
Published: 2018-11-16T14:29:00.393
Modified: 2024-11-21T04:14:55.127
Link: CVE-2018-9073
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD