CVE-2018-9085

A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:lenovo:flex_system_x240_m4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:flex_system_x240_m4:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:lenovo:flex_system_x440_m4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:flex_system_x440_m4:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:lenovo:system_x3750_m4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:system_x3750_m4:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:ibm:bladecenter_hs23_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hs23:-:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:ibm:bladecenter_hs23e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hs23e:-:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:ibm:flex_system_x220_m4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:flex_system_x220:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:ibm:flex_system_x222_m4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:flex_system_x222_m4:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:ibm:flex_system_x240_m4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:flex_system_x240_m4:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:ibm:flex_system_x280_x6_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:flex_system_x280_x6:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:ibm:flex_system_x440_m4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:flex_system_x440_m4:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:ibm:flex_system_x480_x6_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:flex_system_x480_x6:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:ibm:flex_system_x880_x6_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:flex_system_x880_x6:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:ibm:idataplex_dx360_m4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:idataplex_dx360_m4_:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:ibm:idataplex_dx360_m4_water_cooled_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:idataplex_dx360_m4_:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:ibm:system_x3100_m4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_x3100_m4:*:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:ibm:system_x3100_m5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_x3100_m5:*:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:ibm:system_x3250_m4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_x3250_m4:*:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:ibm:system_x3250_m5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_x3250_m5:*:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:ibm:system_x3300_m4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_x3300_m4:*:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:ibm:system_x3500_m4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_x3500_m4:*:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:ibm:system_x3530_m4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_x3530_m4:*:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:ibm:system_x3550_m4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_x3550_m4:*:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:ibm:system_x3630_m4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_x3630_m4:*:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:ibm:system_x3650_m4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_x3650_m4:*:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:ibm:system_x3650_m4_bd_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_x3650_m4_bd:*:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:ibm:system_x3650_m4_hd_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_x3650_m4_hd:*:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:ibm:system_x3750_m4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_x3750_m4:*:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:ibm:system_x3850_x6_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_x3850_x6:*:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:ibm:system_x3950_x6_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_x3950_x6:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:14

Type Values Removed Values Added
References () https://support.lenovo.com/us/en/solutions/LEN-24477 - Vendor Advisory () https://support.lenovo.com/us/en/solutions/LEN-24477 - Vendor Advisory

Information

Published : 2018-11-16 14:29

Updated : 2024-11-21 04:14


NVD link : CVE-2018-9085

Mitre link : CVE-2018-9085

CVE.ORG link : CVE-2018-9085


JSON object : View

Products Affected

ibm

  • system_x3950_x6
  • flex_system_x222_m4
  • system_x3750_m4_firmware
  • flex_system_x280_x6_firmware
  • system_x3100_m5
  • flex_system_x240_m4_firmware
  • flex_system_x480_x6
  • flex_system_x240_m4
  • system_x3500_m4
  • flex_system_x222_m4_firmware
  • idataplex_dx360_m4_firmware
  • flex_system_x440_m4_firmware
  • system_x3100_m5_firmware
  • system_x3750_m4
  • flex_system_x880_x6
  • system_x3250_m5
  • system_x3500_m4_firmware
  • system_x3950_x6_firmware
  • system_x3630_m4_firmware
  • system_x3650_m4
  • system_x3550_m4
  • flex_system_x480_x6_firmware
  • system_x3650_m4_bd_firmware
  • idataplex_dx360_m4_
  • system_x3530_m4_firmware
  • bladecenter
  • flex_system_x880_x6_firmware
  • system_x3250_m4_firmware
  • system_x3250_m5_firmware
  • system_x3650_m4_bd
  • system_x3250_m4
  • system_x3630_m4
  • bladecenter_hs23_firmware
  • system_x3650_m4_hd_firmware
  • system_x3650_m4_hd
  • system_x3300_m4
  • system_x3550_m4_firmware
  • system_x3850_x6_firmware
  • flex_system_x220
  • system_x3100_m4
  • system_x3530_m4
  • bladecenter_hs23e_firmware
  • idataplex_dx360_m4_water_cooled_firmware
  • system_x3300_m4_firmware
  • system_x3850_x6
  • system_x3650_m4_firmware
  • flex_system_x280_x6
  • system_x3100_m4_firmware
  • flex_system_x220_m4_firmware
  • flex_system_x440_m4

lenovo

  • flex_system_x440_m4
  • system_x3750_m4_firmware
  • flex_system_x240_m4_firmware
  • flex_system_x240_m4
  • flex_system_x440_m4_firmware
  • system_x3750_m4
CWE
CWE-276

Incorrect Default Permissions