ZeroHour

CVE-2018-9085

CVSS 3.0
4.9 medium
EPSS
<1%p50
Published
()
Modified
Description

A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.

Vendors
lenovoibm
Products
flex system x240 m4 firmware, flex system x440 m4 firmware, system x3750 m4 firmware, bladecenter hs23 firmware, bladecenter hs23e firmware, flex system x220 m4 firmware, flex system x222 m4 firmware, flex system x280 x6 firmware, flex system x480 x6 firmware, flex system x880 x6 firmware, idataplex dx360 m4 firmware, idataplex dx360 m4 water cooled firmware
Weakness
CWE-276
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.