Vulnerability Details CVE-2018-9073
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 36.1%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 4.3
Products affected by CVE-2018-9073
-
cpe:2.3:h:lenovo:chassis_management_module:-
-
cpe:2.3:o:lenovo:chassis_management_module_firmware:1.6.1
-
cpe:2.3:o:lenovo:chassis_management_module_firmware:1.7.0
-
cpe:2.3:o:lenovo:chassis_management_module_firmware:1.8.0
-
cpe:2.3:o:lenovo:chassis_management_module_firmware:1.9.0