Remote Command Logging Vulnerability in Lenovo System x Servers
CVE-2017-3744
What is CVE-2017-3744?
The IMM2 firmware in Lenovo System x servers contains a vulnerability that allows remote commands initiated by tools such as LXCA to be logged in the First Failure Data Capture (FFDC) service logs. If the FFDC log is generated while the command is executing, it may inadvertently capture sensitive information, including clear text login credentials. This access to exported FFDC logs can pose significant risks for authorized users, who may gain unauthorized visibility into remote command data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Lenovo System x IMM2 Lenovo System x IMM2 firmware versions earlier than 4.10 and IBM System x IMM2 firmware versions earlier than 6.20
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved