CVE Feed

    Dashboard / CVE / CVE-2017-3744

    CVE-2017-3744

    In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command data may contain clear text login information. Authorized users that can capture and export FFDC service log data may have access to these remote commands.

    Published:Jun 20, 2017
    Last Modified:Apr 20, 2025
    EPS:Jun 20, 2017
    EPSS Score:0.00264
    CVSS Score:6.5

    Affected Products

    Vendor
    Ibm
    Product
    Bladecenter Hs22
    Vendor
    Ibm
    Product
    Bladecenter Hs23
    Vendor
    Ibm
    Product
    Bladecenter Hs23e
    Vendor
    Ibm
    Product
    Flex System X220 M4
    Vendor
    Ibm
    Product
    Flex System X222 M4
    Vendor
    Ibm
    Product
    Flex System X240 M4
    Vendor
    Ibm
    Product
    Flex System X280 M4
    Vendor
    Ibm
    Product
    Flex System X440 M4
    Vendor
    Ibm
    Product
    Flex System X480 M4
    Vendor
    Ibm
    Product
    Flex System X880 M4
    Vendor
    Ibm
    Product
    Idataplex Dx360 M4
    Vendor
    Ibm
    Product
    Idataplex Dx360 M4 Water Cooled
    Vendor
    Ibm
    Product
    Integrated Management Module Firmware
    Vendor
    Ibm
    Product
    Nextscale Nx360 M4
    Vendor
    Ibm
    Product
    System X3100 M4
    Vendor
    Ibm
    Product
    System X3100 M5
    Vendor
    Ibm
    Product
    System X3250 M4
    Vendor
    Ibm
    Product
    System X3250 M5
    Vendor
    Ibm
    Product
    System X3300 M4
    Vendor
    Ibm
    Product
    System X3500 M4
    Vendor
    Ibm
    Product
    System X3530 M4
    Vendor
    Ibm
    Product
    System X3550 M4
    Vendor
    Ibm
    Product
    System X3630 M4
    Vendor
    Ibm
    Product
    System X3650 M4
    Vendor
    Ibm
    Product
    System X3650 M4 Bd
    Vendor
    Ibm
    Product
    System X3650 M4 Hd
    Vendor
    Ibm
    Product
    System X3750 M4
    Vendor
    Ibm
    Product
    System X3850 X6
    Vendor
    Ibm
    Product
    System X3950 X6
    Vendor
    Lenovo
    Product
    Flex System X240 M4
    Vendor
    Lenovo
    Product
    Flex System X240 M5
    Vendor
    Lenovo
    Product
    Flex System X280 X6
    Vendor
    Lenovo
    Product
    Flex System X440 M4
    Vendor
    Lenovo
    Product
    Flex System X480 X6
    Vendor
    Lenovo
    Product
    Flex System X880
    Vendor
    Lenovo
    Product
    Integrated Management Module Firmware
    Vendor
    Lenovo
    Product
    Nextscale Nx360 M5
    Vendor
    Lenovo
    Product
    System X3250 M6
    Vendor
    Lenovo
    Product
    System X3500 M5
    Vendor
    Lenovo
    Product
    System X3550 M5
    Vendor
    Lenovo
    Product
    System X3650 M5
    Vendor
    Lenovo
    Product
    System X3750 M4
    Vendor
    Lenovo
    Product
    System X3850 X6
    Vendor
    Lenovo
    Product
    System X3950 X6
    Vendor
    Lenovo
    Product
    Thinkagile Cx2200
    Vendor
    Lenovo
    Product
    Thinkagile Cx4200
    Vendor
    Lenovo
    Product
    Thinkagile Cx4600

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High