CVE-2017-3774: Buffer Overflow
A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than version 4.70 used in some Lenovo servers and earlier than version 6.60 used in some IBM servers. An attacker providing a crafted user ID and password combination can cause a portion of the authentication routine to overflow its stack, resulting in stack corruption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3774?
CVE-2017-3774 has been classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2017-3774?
To address CVE-2017-3774, upgrade the firmware of the Integrated Management Module 2 to version 4.70 or later for Lenovo servers and version 6.60 or later for IBM servers.
What systems are affected by CVE-2017-3774?
CVE-2017-3774 affects Integrated Management Module 2 versions earlier than 4.70 for Lenovo servers and versions earlier than 6.60 for IBM servers.
What type of vulnerability is CVE-2017-3774?
CVE-2017-3774 is a stack overflow vulnerability that could be exploited through crafted user credentials.
Can CVE-2017-3774 be exploited remotely?
Yes, CVE-2017-3774 can be exploited remotely, allowing an attacker to gain unauthorized access to affected systems.