CVE-2018-9083
Last modified
CVE-2018-9083 is a vulnerability of currently unknown severity. In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.. EPSS estimates a 1.07% chance of exploitation in the next 30 days.
Description
In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | System Management Module Firmware | < 1.06 |
References
- https://support.lenovo.com/us/en/solutions/LEN-24374Vendor Advisory
- https://support.lenovo.com/us/en/solutions/LEN-24374Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-9083?
How severe is CVE-2018-9083?
How do I fix CVE-2018-9083?
Are you affected by CVE-2018-9083?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
