In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged user to download and execute arbitrary code inside the BMC. This can only be exploited by authorized privileged users.
2018-11-16T14:29:00.457
2024-11-21T04:14:56.983
Modified
CVSSv3.0: 7.2 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | lenovo | thinkserver_rd340_firmware | < 64.00 | Yes |
Hardware | lenovo | thinkserver_rd340 | - | No |
Operating System | lenovo | thinkserver_rd440_firmware | < 64.00 | Yes |
Hardware | lenovo | thinkserver_rd440 | - | No |
Operating System | lenovo | thinkserver_rd640_firmware | < 64.00 | Yes |
Hardware | lenovo | thinkserver_rd640 | - | No |
Operating System | lenovo | thinkserver_td340_firmware | < 60.00 | Yes |
Hardware | lenovo | thinkserver_td340 | - | No |