A command injection vulnerability was reported in the Integrated Management Module (IMM) of legacy IBM System x 3550 M3 and IBM System x 3650 M3 servers that could allow the execution of operating system commands over an authenticated SSH or Telnet session.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-27003 A command injection vulnerability was reported in the Integrated Management Module (IMM) of legacy IBM System x 3550 M3 and IBM System x 3650 M3 servers that could allow the execution of operating system commands over an authenticated SSH or Telnet session.
Fixes

Solution

No solution given by the vendor.


Workaround

Lenovo has ended support for legacy IBM System x 3550 M3 and IBM System x 3650 M3 servers as of December 31, 2019, therefore Lenovo recommends discontinuation of use. If it is not feasible to discontinue use of these systems, Lenovo recommends customers: Disable SSH and Telnet (This can be done in the Security and Network Protocol sections of the navigation pane after logging into the IMM web interface) Change the default Administrator password during initial configuration Enforce strong passwords Only grant access to trusted administrators

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-03T17:01:07.696Z

Reserved: 2021-08-18T00:00:00

Link: CVE-2021-3723

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-11-12T22:15:08.057

Modified: 2024-11-21T06:22:15.303

Link: CVE-2021-3723

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses