HIGH · 8.1

CVE-2018-16092

In System Management Module (SMM) versions prior to 1.06, the FFDC feature includes the collection of SMM system files containing sensitive information; notably, the SMM user account credentials and t...

Vulnerability Description

In System Management Module (SMM) versions prior to 1.06, the FFDC feature includes the collection of SMM system files containing sensitive information; notably, the SMM user account credentials and the system shadow file.

CVSS Score

8.1

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LenovoSystem Management Module Firmware< 1.06
LenovoThinkagile Hx Enclosure 7X81-
LenovoThinkagile Hx Enclosure 7Y87-
LenovoThinkagile Hx Enclosure 7Z02-
LenovoThinkagile Vx Enclosure 7Y11-
LenovoThinkagile Vx Enclosure 7Y91-
LenovoThinksystem D2 Enclosure 7X20-
LenovoThinksystem Modular Enclosure 7X22-

References

FAQ

What is CVE-2018-16092?

CVE-2018-16092 is a vulnerability with a CVSS score of 8.1 (HIGH). In System Management Module (SMM) versions prior to 1.06, the FFDC feature includes the collection of SMM system files containing sensitive information; notably, the SMM user account credentials and t...

How severe is CVE-2018-16092?

CVE-2018-16092 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-16092?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo System Management Module Firmware, Lenovo Thinkagile Hx Enclosure 7X81, Lenovo Thinkagile Hx Enclosure 7Y87, Lenovo Thinkagile Hx Enclosure 7Z02, Lenovo Thinkagile Vx Enclosure 7Y11.