CVE-2018-16089
System Management Module Vulnerabilities
Severity Score
7.5
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user.
En System Management Module (SMM), en versiones anteriores a la 1.06, un campo en la cabecera de las imágenes de actualización del firmware de SMM no está lo suficientemente saneado, lo que permite una inyección de comandos tras la autenticación en el SMM como el usuario root.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2018-08-29 CVE Reserved
- 2018-11-27 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.lenovo.com/us/en/solutions/LEN-24374 | 2019-10-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Lenovo Search vendor "Lenovo" | System Management Module Firmware Search vendor "Lenovo" for product "System Management Module Firmware" | < 1.06 Search vendor "Lenovo" for product "System Management Module Firmware" and version " < 1.06" | - |
Affected
| in | Lenovo Search vendor "Lenovo" | Thinkagile Hx Enclosure 7x81 Search vendor "Lenovo" for product "Thinkagile Hx Enclosure 7x81" | - | - |
Safe
|
Lenovo Search vendor "Lenovo" | System Management Module Firmware Search vendor "Lenovo" for product "System Management Module Firmware" | < 1.06 Search vendor "Lenovo" for product "System Management Module Firmware" and version " < 1.06" | - |
Affected
| in | Lenovo Search vendor "Lenovo" | Thinkagile Hx Enclosure 7y87 Search vendor "Lenovo" for product "Thinkagile Hx Enclosure 7y87" | - | - |
Safe
|
Lenovo Search vendor "Lenovo" | System Management Module Firmware Search vendor "Lenovo" for product "System Management Module Firmware" | < 1.06 Search vendor "Lenovo" for product "System Management Module Firmware" and version " < 1.06" | - |
Affected
| in | Lenovo Search vendor "Lenovo" | Thinkagile Hx Enclosure 7z02 Search vendor "Lenovo" for product "Thinkagile Hx Enclosure 7z02" | - | - |
Safe
|
Lenovo Search vendor "Lenovo" | System Management Module Firmware Search vendor "Lenovo" for product "System Management Module Firmware" | < 1.06 Search vendor "Lenovo" for product "System Management Module Firmware" and version " < 1.06" | - |
Affected
| in | Lenovo Search vendor "Lenovo" | Thinkagile Vx Enclosure 7y11 Search vendor "Lenovo" for product "Thinkagile Vx Enclosure 7y11" | - | - |
Safe
|
Lenovo Search vendor "Lenovo" | System Management Module Firmware Search vendor "Lenovo" for product "System Management Module Firmware" | < 1.06 Search vendor "Lenovo" for product "System Management Module Firmware" and version " < 1.06" | - |
Affected
| in | Lenovo Search vendor "Lenovo" | Thinkagile Vx Enclosure 7y91 Search vendor "Lenovo" for product "Thinkagile Vx Enclosure 7y91" | - | - |
Safe
|
Lenovo Search vendor "Lenovo" | System Management Module Firmware Search vendor "Lenovo" for product "System Management Module Firmware" | < 1.06 Search vendor "Lenovo" for product "System Management Module Firmware" and version " < 1.06" | - |
Affected
| in | Lenovo Search vendor "Lenovo" | Thinksystem D2 Enclosure 7x20 Search vendor "Lenovo" for product "Thinksystem D2 Enclosure 7x20" | - | - |
Safe
|
Lenovo Search vendor "Lenovo" | System Management Module Firmware Search vendor "Lenovo" for product "System Management Module Firmware" | < 1.06 Search vendor "Lenovo" for product "System Management Module Firmware" and version " < 1.06" | - |
Affected
| in | Lenovo Search vendor "Lenovo" | Thinksystem Modular Enclosure 7x22 Search vendor "Lenovo" for product "Thinksystem Modular Enclosure 7x22" | - | - |
Safe
|