CVE-2018-9085

UnknownEPSS 0.66%

Last modified

CVE-2018-9085 is a vulnerability of currently unknown severity. A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.. EPSS estimates a 0.66% chance of exploitation in the next 30 days.

Description

A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.

Metrics

EPSS Probability
0.66%

47.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LenovoFlex System X240 M4 Firmware< a3e122b
LenovoFlex System X440 M4 Firmware< cge122b
LenovoSystem X3750 M4 Firmware< a5e124b
IbmBladecenter Hs23 Firmware< tke160c
IbmBladecenter Hs23e Firmware< ahe160c
IbmFlex System X220 M4 Firmware< kse158c
IbmFlex System X222 M4 Firmware< cce160c
IbmFlex System X240 M4 Firmware< ahe160c
IbmFlex System X280 X6 Firmware< n3e132w
IbmFlex System X440 M4 Firmware< cne162d
IbmFlex System X480 X6 Firmware< n3e132w
IbmFlex System X880 X6 Firmware< n2e130e
IbmIdataplex Dx360 M4 Firmware< fhe120d
IbmIdataplex Dx360 M4 Water Cooled Firmware< fhe120d
IbmSystem X3100 M4 Firmware< jqe184c
IbmSystem X3100 M5 Firmware< j9e134c
IbmSystem X3250 M4 Firmware< jqe184c
IbmSystem X3250 M5 Firmware< jue134c
IbmSystem X3300 M4 Firmware< yae156c
IbmSystem X3500 M4 Firmware< y5e158c
IbmSystem X3530 M4 Firmware< bee164c
IbmSystem X3550 M4 Firmware< d7e166d
IbmSystem X3630 M4 Firmware< vve162c
IbmSystem X3650 M4 Firmware< vve160c
IbmSystem X3650 M4 Bd Firmware< vve160c
IbmSystem X3650 M4 Hd Firmware< vve160c
IbmSystem X3750 M4 Firmware< koe160c
IbmSystem X3850 X6 Firmware< a8e128c
IbmSystem X3950 X6 Firmware< bee164c

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-9085?
A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.
How severe is CVE-2018-9085?
Severity scoring for CVE-2018-9085 is pending analysis. The EPSS model estimates a 0.66% probability of exploitation in the next 30 days.
How do I fix CVE-2018-9085?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-9085?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST