Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-9068


The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on the IMM2 management network interface. In versions earlier than 4.90 for Lenovo System x and earlier than 6.80 for IBM System x, the credentials to access the SFTP server are hard-coded and described in the IMM2 documentation, allowing an attacker with management network access to obtain the collected FFDC data. After applying the update, the IMM2 will create random SFTP credentials for use with OneCLI.


Published

2018-07-26T19:29:00.487

Last Modified

2024-11-21T04:14:54.413

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-798

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System lenovo flex_system_x240_m4_firmware < 4.90 Yes
Hardware lenovo flex_system_x240_m4 - No
Operating System lenovo flex_system_x240_m5_firmware < 4.90 Yes
Hardware lenovo flex_system_x240_m5 - No
Operating System lenovo flex_system_x280_x6_firmware < 4.90 Yes
Hardware lenovo flex_system_x280_x6 - No
Operating System lenovo flex_system_x440_m4_firmware < 4.90 Yes
Hardware lenovo flex_system_x440_m4 - No
Operating System lenovo flex_system_x480_x6_firmware < 4.90 Yes
Hardware lenovo flex_system_x480_x6 - No
Operating System lenovo flex_system_x880_firmware < 4.90 Yes
Hardware lenovo flex_system_x880 - No
Operating System lenovo nextscale_nx360_m5_firmware < 4.90 Yes
Hardware lenovo nextscale_nx360_m5 - No
Operating System lenovo system_x3250_m6_firmware < 4.90 Yes
Hardware lenovo system_x3250_m6 - No
Operating System lenovo system_x3500_m5_firmware < 4.90 Yes
Hardware lenovo system_x3500_m5 - No
Operating System lenovo system_x3550_m5_firmware < 4.90 Yes
Hardware lenovo system_x3550_m5 - No
Operating System lenovo system_x3650_m5_firmware < 4.90 Yes
Hardware lenovo system_x3650_m5 - No
Operating System lenovo system_x3750_m4_firmware < 4.90 Yes
Hardware lenovo system_x3750_m4 - No
Operating System lenovo system_x3850_x6_firmware < 4.90 Yes
Hardware lenovo system_x3850_x6 - No
Operating System lenovo system_x3950_x6_firmware < 4.90 Yes
Hardware lenovo system_x3950_x6 - No
Operating System ibm bladecenter_hs22_firmware < 6.80 Yes
Hardware ibm bladecenter_hs22 - No
Operating System ibm bladecenter_hs23_firmware < 6.80 Yes
Hardware ibm bladecenter_hs23 - No
Operating System ibm bladecenter_hs23e_firmware < 6.80 Yes
Hardware ibm bladecenter_hs23e - No
Operating System ibm flex_system_x220_m4_firmware < 6.80 Yes
Hardware ibm flex_system_x220_m4 - No
Operating System ibm flex_system_x222_m4_firmware < 6.80 Yes
Hardware ibm flex_system_x222_m4 - No
Operating System ibm flex_system_x240_m4_firmware < 6.80 Yes
Hardware ibm flex_system_x240_m4 - No
Operating System ibm flex_system_x280_m4_firmware < 6.80 Yes
Hardware ibm flex_system_x280_m4 - No
Operating System ibm flex_system_x440_m4_firmware < 6.80 Yes
Hardware ibm flex_system_x440_m4 - No
Operating System ibm flex_system_x480_m4_firmware < 6.80 Yes
Hardware ibm flex_system_x480_m4 - No
Operating System ibm flex_system_x880_m4_firmware < 6.80 Yes
Hardware ibm flex_system_x880_m4 - No
Operating System ibm idataplex_dx360_m4_firmware < 6.80 Yes
Hardware ibm idataplex_dx360_m4 - No
Operating System ibm idataplex_dx360_m4_water_cooled_firmware < 6.80 Yes
Hardware ibm idataplex_dx360_m4_water_cooled - No
Operating System ibm nextscale_nx360_m4_firmware < 6.80 Yes
Hardware ibm nextscale_nx360_m4 - No
Operating System ibm system_x3100_m4_firmware < 6.80 Yes
Hardware ibm system_x3100_m4 - No
Operating System ibm system_x3100_m5_firmware < 6.80 Yes
Hardware ibm system_x3100_m5 - No
Operating System ibm system_x3250_m4_firmware < 6.80 Yes
Hardware ibm system_x3250_m4 - No
Operating System ibm system_x3250_m5_firmware < 6.80 Yes
Hardware ibm system_x3250_m5 - No
Operating System ibm system_x3300_m4_firmware < 6.80 Yes
Hardware ibm system_x3300_m4 - No
Operating System ibm system_x3500_m4_firmware < 6.80 Yes
Hardware ibm system_x3500_m4 - No
Operating System ibm system_x3530_m4_firmware < 6.80 Yes
Hardware ibm system_x3530_m4 - No
Operating System ibm system_x3550_m4_firmware < 6.80 Yes
Hardware ibm system_x3550_m4 - No
Operating System ibm system_x3630_m4_firmware < 6.80 Yes
Hardware ibm system_x3630_m4 - No
Operating System ibm system_x3650_m4_firmware < 6.80 Yes
Hardware ibm system_x3650_m4 - No
Operating System ibm system_x3650_m4_bd_firmware < 6.80 Yes
Hardware ibm system_x3650_m4_bd - No
Operating System ibm system_x3650_m4_hd_firmware < 6.80 Yes
Hardware ibm system_x3650_m4_hd - No
Operating System ibm system_x3750_m4_firmware < 6.80 Yes
Hardware ibm system_x3750_m4 - No
Operating System ibm system_x3850_x6_firmware < 6.80 Yes
Hardware ibm system_x3850_x6 - No
Operating System ibm system_x3950_x6_firmware < 6.80 Yes
Hardware ibm system_x3950_x6 - No

References