CVE-2018-9085
Last modified
CVE-2018-9085 is a vulnerability of currently unknown severity. A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Flex System X240 M4 Firmware | < a3e122b |
| Lenovo | Flex System X440 M4 Firmware | < cge122b |
| Lenovo | System X3750 M4 Firmware | < a5e124b |
| Ibm | Bladecenter Hs23 Firmware | < tke160c |
| Ibm | Bladecenter Hs23e Firmware | < ahe160c |
| Ibm | Flex System X220 M4 Firmware | < kse158c |
| Ibm | Flex System X222 M4 Firmware | < cce160c |
| Ibm | Flex System X240 M4 Firmware | < ahe160c |
| Ibm | Flex System X280 X6 Firmware | < n3e132w |
| Ibm | Flex System X440 M4 Firmware | < cne162d |
| Ibm | Flex System X480 X6 Firmware | < n3e132w |
| Ibm | Flex System X880 X6 Firmware | < n2e130e |
| Ibm | Idataplex Dx360 M4 Firmware | < fhe120d |
| Ibm | Idataplex Dx360 M4 Water Cooled Firmware | < fhe120d |
| Ibm | System X3100 M4 Firmware | < jqe184c |
| Ibm | System X3100 M5 Firmware | < j9e134c |
| Ibm | System X3250 M4 Firmware | < jqe184c |
| Ibm | System X3250 M5 Firmware | < jue134c |
| Ibm | System X3300 M4 Firmware | < yae156c |
| Ibm | System X3500 M4 Firmware | < y5e158c |
| Ibm | System X3530 M4 Firmware | < bee164c |
| Ibm | System X3550 M4 Firmware | < d7e166d |
| Ibm | System X3630 M4 Firmware | < vve162c |
| Ibm | System X3650 M4 Firmware | < vve160c |
| Ibm | System X3650 M4 Bd Firmware | < vve160c |
| Ibm | System X3650 M4 Hd Firmware | < vve160c |
| Ibm | System X3750 M4 Firmware | < koe160c |
| Ibm | System X3850 X6 Firmware | < a8e128c |
| Ibm | System X3950 X6 Firmware | < bee164c |
References
- https://support.lenovo.com/us/en/solutions/LEN-24477Vendor Advisory
- https://support.lenovo.com/us/en/solutions/LEN-24477Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-9085?
How severe is CVE-2018-9085?
How do I fix CVE-2018-9085?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-9079For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.…
- CVE-2018-9080For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.…
- CVE-2018-9081For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.…
- CVE-2018-9082For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.…
- CVE-2018-9083In System Management Module (SMM) versions prior to 1.06, th…
- CVE-2018-9084In System Management Module (SMM) versions prior to 1.06, if…
- CVE-2018-9086In some Lenovo ThinkServer-branded servers, a command inject…
- CVE-2018-9090CoreOS Tectonic 1.7.x and 1.8.x before 1.8.7-tectonic.2 depl…6.1
- CVE-2018-9091A critical vulnerability in the KEMP LoadMaster Operating Sy…
- CVE-2018-9092There is a CSRF vulnerability in mc-admin/conf.php in MiniCM…
- CVE-2018-9101A vulnerability in the conferencing component of Mitel MiVoi…
- CVE-2018-9102A vulnerability in the conferencing component of Mitel MiVoi…
Are you affected by CVE-2018-9085?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
