TROYANOSYVIRUS
Back to CVEs

CVE-2018-9073

N/A

Description

Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets.

CVE Details

CVSS v3.1 ScoreN/A
Published11/16/2018
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

lenovo:chassis_management_modulelenovo:chassis_management_module_firmware

Weaknesses (CWE)

CWE-798

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.