SFTP Server Credential Exposure in Lenovo and IBM Management Systems
CVE-2018-9068
7.5HIGH
What is CVE-2018-9068?
The IMM2 Management Module's First Failure Data Capture (FFDC) function is designed to log hardware errors and provide diagnostic information. In certain older versions, the SFTP server credentials for downloading this sensitive data are hard-coded and publicly documented, making them vulnerable to exploitation. Any attacker with access to the management network can gain unauthorized access to this data, risking system integrity and security.
Affected Version(s)
System x IMM2 firmware versions earlier than 4.90
System x IMM2 firmware versions earlier than 6.80