CVE-2017-3744
In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command data may contain clear text login information. Authorized users that can capture and export FFDC service log data may have access to these remote commands.
Published:Jun 20, 2017
Last Modified:Apr 20, 2025
EPS:Jun 20, 2017
EPSS Score:0.00264
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Ibm
Product
Bladecenter Hs22
Ibm
Bladecenter Hs22
Vendor
Ibm
Product
Bladecenter Hs23
Ibm
Bladecenter Hs23
Vendor
Ibm
Product
Bladecenter Hs23e
Ibm
Bladecenter Hs23e
Vendor
Ibm
Product
Flex System X220 M4
Ibm
Flex System X220 M4
Vendor
Ibm
Product
Flex System X222 M4
Ibm
Flex System X222 M4
Vendor
Ibm
Product
Flex System X240 M4
Ibm
Flex System X240 M4
Vendor
Ibm
Product
Flex System X280 M4
Ibm
Flex System X280 M4
Vendor
Ibm
Product
Flex System X440 M4
Ibm
Flex System X440 M4
Vendor
Ibm
Product
Flex System X480 M4
Ibm
Flex System X480 M4
Vendor
Ibm
Product
Flex System X880 M4
Ibm
Flex System X880 M4
Vendor
Ibm
Product
Idataplex Dx360 M4
Ibm
Idataplex Dx360 M4
Vendor
Ibm
Product
Idataplex Dx360 M4 Water Cooled
Ibm
Idataplex Dx360 M4 Water Cooled
Vendor
Ibm
Product
Integrated Management Module Firmware
Ibm
Integrated Management Module Firmware
Vendor
Ibm
Product
Nextscale Nx360 M4
Ibm
Nextscale Nx360 M4
Vendor
Ibm
Product
System X3100 M4
Ibm
System X3100 M4
Vendor
Ibm
Product
System X3100 M5
Ibm
System X3100 M5
Vendor
Ibm
Product
System X3250 M4
Ibm
System X3250 M4
Vendor
Ibm
Product
System X3250 M5
Ibm
System X3250 M5
Vendor
Ibm
Product
System X3300 M4
Ibm
System X3300 M4
Vendor
Ibm
Product
System X3500 M4
Ibm
System X3500 M4
Vendor
Ibm
Product
System X3530 M4
Ibm
System X3530 M4
Vendor
Ibm
Product
System X3550 M4
Ibm
System X3550 M4
Vendor
Ibm
Product
System X3630 M4
Ibm
System X3630 M4
Vendor
Ibm
Product
System X3650 M4
Ibm
System X3650 M4
Vendor
Ibm
Product
System X3650 M4 Bd
Ibm
System X3650 M4 Bd
Vendor
Ibm
Product
System X3650 M4 Hd
Ibm
System X3650 M4 Hd
Vendor
Ibm
Product
System X3750 M4
Ibm
System X3750 M4
Vendor
Ibm
Product
System X3850 X6
Ibm
System X3850 X6
Vendor
Ibm
Product
System X3950 X6
Ibm
System X3950 X6
Vendor
Lenovo
Product
Flex System X240 M4
Lenovo
Flex System X240 M4
Vendor
Lenovo
Product
Flex System X240 M5
Lenovo
Flex System X240 M5
Vendor
Lenovo
Product
Flex System X280 X6
Lenovo
Flex System X280 X6
Vendor
Lenovo
Product
Flex System X440 M4
Lenovo
Flex System X440 M4
Vendor
Lenovo
Product
Flex System X480 X6
Lenovo
Flex System X480 X6
Vendor
Lenovo
Product
Flex System X880
Lenovo
Flex System X880
Vendor
Lenovo
Product
Integrated Management Module Firmware
Lenovo
Integrated Management Module Firmware
Vendor
Lenovo
Product
Nextscale Nx360 M5
Lenovo
Nextscale Nx360 M5
Vendor
Lenovo
Product
System X3250 M6
Lenovo
System X3250 M6
Vendor
Lenovo
Product
System X3500 M5
Lenovo
System X3500 M5
Vendor
Lenovo
Product
System X3550 M5
Lenovo
System X3550 M5
Vendor
Lenovo
Product
System X3650 M5
Lenovo
System X3650 M5
Vendor
Lenovo
Product
System X3750 M4
Lenovo
System X3750 M4
Vendor
Lenovo
Product
System X3850 X6
Lenovo
System X3850 X6
Vendor
Lenovo
Product
System X3950 X6
Lenovo
System X3950 X6
Vendor
Lenovo
Product
Thinkagile Cx2200
Lenovo
Thinkagile Cx2200
Vendor
Lenovo
Product
Thinkagile Cx4200
Lenovo
Thinkagile Cx4200
Vendor
Lenovo
Product
Thinkagile Cx4600
Lenovo
Thinkagile Cx4600
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
