ZeroHour

CVE-2018-9073

CVSS 3.0
5.9 medium
EPSS
<1%p42
Published
()
Modified
Description

Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets.

Vendors
lenovo
Products
chassis management module firmware
Weakness
CWE-798
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.