// For flags

CVE-2018-9086

Legacy Server BMC Remote Command Injection

Severity Score

7.2
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged user to download and execute arbitrary code inside the BMC. This can only be exploited by authorized privileged users.

En algunos servidores de marca Lenovo ThinkServer, existe una vulnerabilidad de inyección de comandos en el comando de descarga del firmware de BMC. Esto permite que un usuario privilegiado descargue y ejecute código arbitrario en el BMC. Esto solo puede ser explotado por usuarios privilegiados autorizados.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-03-27 CVE Reserved
  • 2018-11-16 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Lenovo
Search vendor "Lenovo"
Thinkserver Rd340 Firmware
Search vendor "Lenovo" for product "Thinkserver Rd340 Firmware"
< 64.00
Search vendor "Lenovo" for product "Thinkserver Rd340 Firmware" and version " < 64.00"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkserver Rd340
Search vendor "Lenovo" for product "Thinkserver Rd340"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkserver Rd440 Firmware
Search vendor "Lenovo" for product "Thinkserver Rd440 Firmware"
< 64.00
Search vendor "Lenovo" for product "Thinkserver Rd440 Firmware" and version " < 64.00"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkserver Rd440
Search vendor "Lenovo" for product "Thinkserver Rd440"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkserver Rd640 Firmware
Search vendor "Lenovo" for product "Thinkserver Rd640 Firmware"
< 64.00
Search vendor "Lenovo" for product "Thinkserver Rd640 Firmware" and version " < 64.00"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkserver Rd640
Search vendor "Lenovo" for product "Thinkserver Rd640"
--
Safe
Lenovo
Search vendor "Lenovo"
Thinkserver Td340 Firmware
Search vendor "Lenovo" for product "Thinkserver Td340 Firmware"
< 60.00
Search vendor "Lenovo" for product "Thinkserver Td340 Firmware" and version " < 60.00"
-
Affected
in Lenovo
Search vendor "Lenovo"
Thinkserver Td340
Search vendor "Lenovo" for product "Thinkserver Td340"
--
Safe