CVE-2018-9071
Summary
| CVE | CVE-2018-9071 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-11-16 14:29:00 UTC |
| Updated | 2018-12-20 21:06:00 UTC |
| Description | Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information related to the current authentication configuration settings. Exposed settings relate to password lengths, expiration, and lockout configuration. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Lenovo | Chassis Management Module | - | All | All | All |
| Hardware | Lenovo | Chassis Management Module | - | All | All | All |
| Operating System | Lenovo | Chassis Management Module Firmware | All | All | All | All |
| Operating System | Lenovo | Chassis Management Module Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CMM Security Concerns - Lenovo Support US | CONFIRM | support.lenovo.com | Mitigation, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.