CVE-2020-8332
- EPSS 0.04%
- Published 14.10.2020 22:15:13
- Last modified 21.11.2024 05:38:43
A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.
CVE-2019-6157
- EPSS 0.3%
- Published 22.04.2019 16:29:02
- Last modified 21.11.2024 04:46:02
In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web server's private key in the generated log file for support.
CVE-2018-9085
- EPSS 0.14%
- Published 16.11.2018 14:29:00
- Last modified 21.11.2024 04:14:56
A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services...
CVE-2018-9068
- EPSS 0.25%
- Published 26.07.2018 19:29:00
- Last modified 21.11.2024 04:14:54
The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on the IMM2 management network in...