ZeroHour

CVE-2018-9083

CVSS 3.0
8.1 high
EPSS
1%p63
Published
()
Modified
Description

In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.

Vendors
lenovo
Products
system management module firmware
Weakness
CWE-798
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.