MEDIUM · 6.5

CVE-2017-3744

In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated ...

Vulnerability Description

In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command data may contain clear text login information. Authorized users that can capture and export FFDC service log data may have access to these remote commands.

CVSS Score

6.5

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
LenovoIntegrated Management Module Firmware<= 4.9
LenovoFlex System X240 M4-
LenovoFlex System X240 M5-
LenovoFlex System X280 X6-
LenovoFlex System X440 M4-
LenovoFlex System X480 X6-
LenovoFlex System X880-
LenovoNextscale Nx360 M5-
LenovoSystem X3250 M6-
LenovoSystem X3500 M5-
LenovoSystem X3550 M5-
LenovoSystem X3650 M5-
LenovoSystem X3750 M4-
LenovoSystem X3850 X6-
LenovoSystem X3950 X6-
LenovoThinkagile Cx2200-
LenovoThinkagile Cx4200-
LenovoThinkagile Cx4600-
IbmIntegrated Management Module Firmware<= 6.19
IbmBladecenter Hs22-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-3744?

CVE-2017-3744 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated ...

How severe is CVE-2017-3744?

CVE-2017-3744 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-3744?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Integrated Management Module Firmware, Lenovo Flex System X240 M4, Lenovo Flex System X240 M5, Lenovo Flex System X280 X6, Lenovo Flex System X440 M4.