In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-20686 In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.
Fixes

Solution

Update SMM firmware


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-05T07:17:50.616Z

Reserved: 2018-03-27T00:00:00

Link: CVE-2018-9083

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-11-27T14:29:00.667

Modified: 2024-11-21T04:14:56.557

Link: CVE-2018-9083

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses