6.5
CVSSv2

CVE-2018-9086

Published: 16/11/2018 Updated: 24/08/2020
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged user to download and execute arbitrary code inside the BMC. This can only be exploited by authorized privileged users.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lenovo thinkserver_rd340_firmware

lenovo thinkserver_rd440_firmware

lenovo thinkserver_rd640_firmware

lenovo thinkserver_td340_firmware