Back to search
CVE-2018-9073
Published: Nov 16, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets.
| Vendor | Product | Versions |
|---|---|---|
Lenovo | Chassis Management Module (CMM) | affected unspecified - < 2.0.0 |
References
https://support.lenovo.com/us/en/solutions/LEN-23806
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now