In System Management Module (SMM) versions prior to 1.06, the FFDC feature includes the collection of SMM system files containing sensitive information; notably, the SMM user account credentials and the system shadow file.
2018-11-27T14:29:00.493
2024-11-21T03:52:05.430
Modified
CVSSv3.0: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:P/I:N/A:N
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | lenovo | system_management_module_firmware | < 1.06 | Yes |
| Hardware | lenovo | thinkagile_hx_enclosure_7x81 | - | No |
| Hardware | lenovo | thinkagile_hx_enclosure_7y87 | - | No |
| Hardware | lenovo | thinkagile_hx_enclosure_7z02 | - | No |
| Hardware | lenovo | thinkagile_vx_enclosure_7y11 | - | No |
| Hardware | lenovo | thinkagile_vx_enclosure_7y91 | - | No |
| Hardware | lenovo | thinksystem_d2_enclosure_7x20 | - | No |
| Hardware | lenovo | thinksystem_modular_enclosure_7x22 | - | No |