CVE-2018-9083

HIGH

Lenovo System Management Module Firmware < 1.06 - Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://support.lenovo.com/us/en/solutions/LEN-24374

Scores

CVSS v3 8.1
EPSS 0.0036
EPSS Percentile 58.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (1)
lenovo/system_management_module_firmware < 1.06
Published Nov 27, 2018
Tracked Since Feb 18, 2026