MEDIUM · 6.5

CVE-2019-6157

In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web server's private key in the generated log file for supp...

Vulnerability Description

In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web server's private key in the generated log file for support.

CVSS Score

6.5

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
LenovoFlex System X240 M4 Firmware< 5.30
LenovoFlex System X240 M4-
LenovoFlex System X240 M5 Firmware< 5.30
LenovoFlex System X240 M5-
LenovoFlex System X280 X6 Firmware< 5.30
LenovoFlex System X280 X6-
LenovoFlex System X440 M4 Firmware< 5.30
LenovoFlex System X440 M4-
LenovoFlex System X480 X6 Firmware< 5.30
LenovoFlex System X480 X6-
LenovoFlex System X880 Firmware< 5.30
LenovoFlex System X880-
LenovoNextscale Nx360 M5 Firmware< 5.30
LenovoNextscale Nx360 M5-
LenovoSystem X3250 M6 Firmware< 5.30
LenovoSystem X3250 M6-
LenovoSystem X3500 M5 Firmware< 5.30
LenovoSystem X3500 M5-
LenovoSystem X3550 M5 Firmware< 5.30
LenovoSystem X3550 M5-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-6157?

CVE-2019-6157 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web server's private key in the generated log file for supp...

How severe is CVE-2019-6157?

CVE-2019-6157 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-6157?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Flex System X240 M4 Firmware, Lenovo Flex System X240 M4, Lenovo Flex System X240 M5 Firmware, Lenovo Flex System X240 M5, Lenovo Flex System X280 X6 Firmware.