6.1
CVE-2018-16096
- EPSS 0.3%
- Veröffentlicht 27.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:05
- Quelle psirt@lenovo.com
- Teams Watchlist Login
- Unerledigt Login
In System Management Module (SMM) versions prior to 1.06, the SMM web interface for changing Enclosure VPD fails to sufficiently sanitize all input for HTML tags, possibly opening a path for cross-site scripting.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo ≫ System Management Module Firmware Version < 1.06
Lenovo ≫ Thinkagile Hx Enclosure 7x81 Version-
Lenovo ≫ Thinkagile Hx Enclosure 7y87 Version-
Lenovo ≫ Thinkagile Hx Enclosure 7z02 Version-
Lenovo ≫ Thinkagile Vx Enclosure 7y11 Version-
Lenovo ≫ Thinkagile Vx Enclosure 7y91 Version-
Lenovo ≫ Thinksystem D2 Enclosure 7x20 Version-
Lenovo ≫ Thinksystem Modular Enclosure 7x22 Version-
Lenovo ≫ Thinkagile Hx Enclosure 7y87 Version-
Lenovo ≫ Thinkagile Hx Enclosure 7z02 Version-
Lenovo ≫ Thinkagile Vx Enclosure 7y11 Version-
Lenovo ≫ Thinkagile Vx Enclosure 7y91 Version-
Lenovo ≫ Thinksystem D2 Enclosure 7x20 Version-
Lenovo ≫ Thinksystem Modular Enclosure 7x22 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.3% | 0.503 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.