Vulnerability Description
In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web server's private key in the generated log file for support.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Flex System X240 M4 Firmware | < 5.30 |
| Lenovo | Flex System X240 M4 | - |
| Lenovo | Flex System X240 M5 Firmware | < 5.30 |
| Lenovo | Flex System X240 M5 | - |
| Lenovo | Flex System X280 X6 Firmware | < 5.30 |
| Lenovo | Flex System X280 X6 | - |
| Lenovo | Flex System X440 M4 Firmware | < 5.30 |
| Lenovo | Flex System X440 M4 | - |
| Lenovo | Flex System X480 X6 Firmware | < 5.30 |
| Lenovo | Flex System X480 X6 | - |
| Lenovo | Flex System X880 Firmware | < 5.30 |
| Lenovo | Flex System X880 | - |
| Lenovo | Nextscale Nx360 M5 Firmware | < 5.30 |
| Lenovo | Nextscale Nx360 M5 | - |
| Lenovo | System X3250 M6 Firmware | < 5.30 |
| Lenovo | System X3250 M6 | - |
| Lenovo | System X3500 M5 Firmware | < 5.30 |
| Lenovo | System X3500 M5 | - |
| Lenovo | System X3550 M5 Firmware | < 5.30 |
| Lenovo | System X3550 M5 | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/solutions/LEN-25667PatchVendor Advisory
- https://support.lenovo.com/solutions/LEN-25667PatchVendor Advisory
FAQ
What is CVE-2019-6157?
CVE-2019-6157 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web server's private key in the generated log file for supp...
How severe is CVE-2019-6157?
CVE-2019-6157 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6157?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Flex System X240 M4 Firmware, Lenovo Flex System X240 M4, Lenovo Flex System X240 M5 Firmware, Lenovo Flex System X240 M5, Lenovo Flex System X280 X6 Firmware.