HIGH · 8.1

CVE-2018-16091

In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to several buffer overflows.

Vulnerability Description

In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to several buffer overflows.

CVSS Score

8.1

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LenovoSystem Management Module Firmware< 1.06
LenovoThinkagile Hx Enclosure 7X81-
LenovoThinkagile Hx Enclosure 7Y87-
LenovoThinkagile Hx Enclosure 7Z02-
LenovoThinkagile Vx Enclosure 7Y11-
LenovoThinkagile Vx Enclosure 7Y91-
LenovoThinksystem D2 Enclosure 7X20-
LenovoThinksystem Modular Enclosure 7X22-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-16091?

CVE-2018-16091 is a vulnerability with a CVSS score of 8.1 (HIGH). In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to several buffer overflows.

How severe is CVE-2018-16091?

CVE-2018-16091 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-16091?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo System Management Module Firmware, Lenovo Thinkagile Hx Enclosure 7X81, Lenovo Thinkagile Hx Enclosure 7Y87, Lenovo Thinkagile Hx Enclosure 7Z02, Lenovo Thinkagile Vx Enclosure 7Y11.