CVE-2018-9086

In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged user to download and execute arbitrary code inside the BMC. This can only be exploited by authorized privileged users.
References
Link Resource
https://support.lenovo.com/us/en/solutions/LEN-23836 Patch Third Party Advisory
https://support.lenovo.com/us/en/solutions/LEN-23836 Patch Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_rd340_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd340:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_rd440_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd440:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_rd640_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd640:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_td340_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_td340:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:14

Type Values Removed Values Added
References () https://support.lenovo.com/us/en/solutions/LEN-23836 - Patch, Third Party Advisory () https://support.lenovo.com/us/en/solutions/LEN-23836 - Patch, Third Party Advisory

Information

Published : 2018-11-16 14:29

Updated : 2024-11-21 04:14


NVD link : CVE-2018-9086

Mitre link : CVE-2018-9086

CVE.ORG link : CVE-2018-9086


JSON object : View

Products Affected

lenovo

  • thinkserver_td340
  • thinkserver_rd440_firmware
  • thinkserver_rd340
  • thinkserver_rd640_firmware
  • thinkserver_rd340_firmware
  • thinkserver_td340_firmware
  • thinkserver_rd440
  • thinkserver_rd640
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')