Description
In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.
No analysis available yet.
Remediation
Vendor Solution
Update SMM firmware
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-20686 | In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability. |
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/solutions/LEN-24374 |
|
History
No history.
Subscriptions
Lenovo
Subscribe
System Management Module Firmware
Subscribe
Thinkagile Hx Enclosure 7x81
Subscribe
Thinkagile Hx Enclosure 7y87
Subscribe
Thinkagile Hx Enclosure 7z02
Subscribe
Thinkagile Vx Enclosure 7y11
Subscribe
Thinkagile Vx Enclosure 7y91
Subscribe
Thinksystem D2 Enclosure 7x20
Subscribe
Thinksystem Modular Enclosure 7x22
Subscribe
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-05T07:17:50.616Z
Reserved: 2018-03-27T00:00:00.000Z
Link: CVE-2018-9083
No data.
Status : Modified
Published: 2018-11-27T14:29:00.667
Modified: 2024-11-21T04:14:56.557
Link: CVE-2018-9083
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD