CVE-2018-9086

EUVD-2018-20689
In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged user to download and execute arbitrary code inside the BMC. This can only be exploited by authorized privileged users.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
Affected Products (NVD)
VendorProductVersion
lenovothinkserver_rd340_firmware
𝑥
< 64.00
lenovothinkserver_rd440_firmware
𝑥
< 64.00
lenovothinkserver_rd640_firmware
𝑥
< 64.00
lenovothinkserver_td340_firmware
𝑥
< 60.00
𝑥
= Vulnerable software versions