7 results (0.002 seconds)

CVSS: 7.5EPSS: 0%CPEs: 84EXPL: 0

22 Apr 2019 — In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web server's private key in the generated log file for support. En varias versiones de firmware de Lenovo System x, First Failure Data Capture (FFDC) del módulo de administración integrada II (IMM2) incluye la clave privada del servidor web dentro del archivo de registro generado para soporte. • https://support.lenovo.com/solutions/LEN-25667 • CWE-532: Insertion of Sensitive Information into Log File •

CVSS: 7.5EPSS: 0%CPEs: 84EXPL: 0

26 Jul 2018 — The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on the IMM2 management network interface. In versions earlier than 4.90 for Lenovo System x and earlier than 6.80 for IBM System x, the credentials to access the SFTP server are hard-coded and described in the IMM2 documentation, allowing an attacker with management network access to obtain the... • https://support.lenovo.com/us/en/solutions/LEN-20227 • CWE-798: Use of Hard-coded Credentials •

CVSS: 6.9EPSS: 0%CPEs: 22EXPL: 0

04 May 2018 — Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code. Algunas versiones BIOS/UEFI del servidor x de Lenovo, cuando Secure Boot está habilitado por un administrador del sistema, no autentican correctamente el código firmado antes de cargarlo. Como resultado, un atacante con acceso físico al sistema podría cargar... • https://support.lenovo.com/us/en/solutions/LEN-20241 • CWE-287: Improper Authentication •

CVSS: 9.8EPSS: 0%CPEs: 44EXPL: 0

19 Apr 2018 — A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than version 4.70 used in some Lenovo servers and earlier than version 6.60 used in some IBM servers. An attacker providing a crafted user ID and password combination can cause a portion of the authentication routine to overflow its stack, resulting in stack corruption. Se ha descubierto una vulnerabilidad de desbordamiento de pila en el servicio de administración web en Integ... • https://support.lenovo.com/us/en/product_security/LEN-19586 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 6.5EPSS: 0%CPEs: 47EXPL: 0

20 Jun 2017 — In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command data may contain clear text login information. Authorized users that can capture and export FFDC service log data may have access to these remote commands. En el firmware IMM2 de los servidores Lenovo System x, los comandos remotos enviados por LXCA u otras ... • https://support.lenovo.com/product_security/LEN-14054 • CWE-532: Insertion of Sensitive Information into Log File •

CVSS: 6.8EPSS: 0%CPEs: 11EXPL: 0

26 Jan 2017 — The BIOS in Lenovo System X M5, M6, and X6 systems allows administrators to cause a denial of service via updating a UEFI data structure. La BIOS en sistemas Lenovo System X M5, M6 y X6, permite a administradores provocar una denegación de servicio a través de la actualización de una estructura de datos UEFI. • http://www.securityfocus.com/bid/95844 • CWE-19: Data Processing Errors •

CVSS: 5.9EPSS: 3%CPEs: 60EXPL: 0

09 Jan 2017 — A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows a remote attacker to stop the controller from processing network traffic working under certain network use conditions. Una denegación de servicio en Intel Ethernet Controller's X710/XL710 con Non-Volatile Memory Images en versiones anteriores a 5.05 permite a atacantes remotos detener el controlador de procesar el tráfico de red que funciona bajo determinadas condiciones de uso de la red.... • http://www-01.ibm.com/support/docview.wss?uid=swg22002507 • CWE-20: Improper Input Validation •