CVE-2018-16096: System Management Module Vulnerabilities
In System Management Module (SMM) versions prior to 1.06, the SMM web interface for changing Enclosure VPD fails to sufficiently sanitize all input for HTML tags, possibly opening a path for cross-site scripting.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2018-16096?
CVE-2018-16096 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2018-16096?
To fix CVE-2018-16096, upgrade the System Management Module firmware to version 1.06 or later.
What software is affected by CVE-2018-16096?
CVE-2018-16096 affects Lenovo System Management Module firmware versions prior to 1.06.
What vulnerabilities are associated with the SMM web interface in CVE-2018-16096?
CVE-2018-16096 is associated with insufficient sanitization of input for HTML tags, leading to potential cross-site scripting.
Is CVE-2018-16096 still a risk for users of SMM firmware version 1.06 and above?
No, users of SMM firmware version 1.06 and above are not at risk for CVE-2018-16096 as the vulnerability has been addressed.