CVE-2018-9073
16.11.2018, 14:29
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets.Enginsight
Vendor | Product | Version |
---|---|---|
lenovo | chassis_management_module_firmware | 𝑥 < 2.0.0 |
𝑥
= Vulnerable software versions