CVE-2018-16089
In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user.
Published:Nov 27, 2018
Last Modified:Nov 21, 2024
EPS:Nov 27, 2018
EPSS Score:0.01066
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Lenovo
Product
System Management Module Firmware
Lenovo
System Management Module Firmware
Vendor
Lenovo
Product
Thinkagile Hx Enclosure 7x81
Lenovo
Thinkagile Hx Enclosure 7x81
Vendor
Lenovo
Product
Thinkagile Hx Enclosure 7y87
Lenovo
Thinkagile Hx Enclosure 7y87
Vendor
Lenovo
Product
Thinkagile Hx Enclosure 7z02
Lenovo
Thinkagile Hx Enclosure 7z02
Vendor
Lenovo
Product
Thinkagile Vx Enclosure 7y11
Lenovo
Thinkagile Vx Enclosure 7y11
Vendor
Lenovo
Product
Thinkagile Vx Enclosure 7y91
Lenovo
Thinkagile Vx Enclosure 7y91
Vendor
Lenovo
Product
Thinksystem D2 Enclosure 7x20
Lenovo
Thinksystem D2 Enclosure 7x20
Vendor
Lenovo
Product
Thinksystem Modular Enclosure 7x22
Lenovo
Thinksystem Modular Enclosure 7x22
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
