// For flags

CVE-2018-9073

CMM Security Vulnerability

Severity Score

5.9
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets.

Lenovo Chassis Management Module (CMM) en versiones anteriores a la 2.0.0 emplea una clave de cifrado embebida para proteger ciertos secretos. Poseer esta clave puede permitir a un atacante que ya haya comprometido el servidor descifrar estos secretos.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-03-27 CVE Reserved
  • 2018-11-16 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-798: Use of Hard-coded Credentials
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Lenovo
Search vendor "Lenovo"
Chassis Management Module Firmware
Search vendor "Lenovo" for product "Chassis Management Module Firmware"
< 2.0.0
Search vendor "Lenovo" for product "Chassis Management Module Firmware" and version " < 2.0.0"
-
Affected
in Lenovo
Search vendor "Lenovo"
Chassis Management Module
Search vendor "Lenovo" for product "Chassis Management Module"
--
Safe