System Management Module Vulnerabilities
CVE-2018-16096

6.1MEDIUM

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
27 November 2018

Summary

In System Management Module (SMM) versions prior to 1.06, the SMM web interface for changing Enclosure VPD fails to sufficiently sanitize all input for HTML tags, possibly opening a path for cross-site scripting.

Affected Version(s)

ThinkSystem SMM < 1.06

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.