CVE-2018-9086

In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged user to download and execute arbitrary code inside the BMC. This can only be exploited by authorized privileged users.
References
Link Resource
https://support.lenovo.com/us/en/solutions/LEN-23836 Patch Third Party Advisory
Configurations

Configuration 1


Information

Published : 2018-11-16 02:29

Updated : 2020-08-24 05:37


NVD link : CVE-2018-9086

Mitre link : CVE-2018-9086

Products Affected
No products.
CWE