Vulnerability Description
In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command data may contain clear text login information. Authorized users that can capture and export FFDC service log data may have access to these remote commands.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Integrated Management Module Firmware | <= 4.9 |
| Lenovo | Flex System X240 M4 | - |
| Lenovo | Flex System X240 M5 | - |
| Lenovo | Flex System X280 X6 | - |
| Lenovo | Flex System X440 M4 | - |
| Lenovo | Flex System X480 X6 | - |
| Lenovo | Flex System X880 | - |
| Lenovo | Nextscale Nx360 M5 | - |
| Lenovo | System X3250 M6 | - |
| Lenovo | System X3500 M5 | - |
| Lenovo | System X3550 M5 | - |
| Lenovo | System X3650 M5 | - |
| Lenovo | System X3750 M4 | - |
| Lenovo | System X3850 X6 | - |
| Lenovo | System X3950 X6 | - |
| Lenovo | Thinkagile Cx2200 | - |
| Lenovo | Thinkagile Cx4200 | - |
| Lenovo | Thinkagile Cx4600 | - |
| Ibm | Integrated Management Module Firmware | <= 6.19 |
| Ibm | Bladecenter Hs22 | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/product_security/LEN-14054Vendor Advisory
- https://support.lenovo.com/product_security/LEN-14054Vendor Advisory
FAQ
What is CVE-2017-3744?
CVE-2017-3744 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated ...
How severe is CVE-2017-3744?
CVE-2017-3744 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-3744?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Integrated Management Module Firmware, Lenovo Flex System X240 M4, Lenovo Flex System X240 M5, Lenovo Flex System X280 X6, Lenovo Flex System X440 M4.