Vulnerability Description
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Chassis Management Module Firmware | < 2.0.0 |
| Lenovo | Chassis Management Module | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/solutions/LEN-23806Vendor Advisory
- https://support.lenovo.com/us/en/solutions/LEN-23806Vendor Advisory
FAQ
What is CVE-2018-9073?
CVE-2018-9073 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised t...
How severe is CVE-2018-9073?
CVE-2018-9073 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-9073?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Chassis Management Module Firmware, Lenovo Chassis Management Module.