Vulnerability Description
A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Flex System X240 M4 Firmware | < a3e122b |
| Lenovo | Flex System X240 M4 | - |
| Lenovo | Flex System X440 M4 Firmware | < cge122b |
| Lenovo | Flex System X440 M4 | - |
| Lenovo | System X3750 M4 Firmware | < a5e124b |
| Lenovo | System X3750 M4 | - |
| Ibm | Bladecenter Hs23 Firmware | < tke160c |
| Ibm | Bladecenter | hs23 |
| Ibm | Bladecenter Hs23E Firmware | < ahe160c |
| Ibm | Flex System X220 M4 Firmware | < kse158c |
| Ibm | Flex System X220 | - |
| Ibm | Flex System X222 M4 Firmware | < cce160c |
| Ibm | Flex System X222 M4 | - |
| Ibm | Flex System X240 M4 Firmware | < ahe160c |
| Ibm | Flex System X240 M4 | - |
| Ibm | Flex System X280 X6 Firmware | < n3e132w |
| Ibm | Flex System X280 X6 | - |
| Ibm | Flex System X440 M4 Firmware | < cne162d |
| Ibm | Flex System X440 M4 | - |
| Ibm | Flex System X480 X6 Firmware | < n3e132w |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/solutions/LEN-24477Vendor Advisory
- https://support.lenovo.com/us/en/solutions/LEN-24477Vendor Advisory
FAQ
What is CVE-2018-9085?
CVE-2018-9085 is a vulnerability with a CVSS score of 4.9 (MEDIUM). A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flas...
How severe is CVE-2018-9085?
CVE-2018-9085 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-9085?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Flex System X240 M4 Firmware, Lenovo Flex System X240 M4, Lenovo Flex System X440 M4 Firmware, Lenovo Flex System X440 M4, Lenovo System X3750 M4 Firmware.