CVE-2018-9083: System Management Module Vulnerabilities
In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9083?
CVE-2018-9083 has a critical severity rating due to the presence of weak default root credentials allowing unauthorized access.
How do I fix CVE-2018-9083?
To fix CVE-2018-9083, update the Lenovo System Management Module firmware to version 1.06 or later.
What devices are affected by CVE-2018-9083?
CVE-2018-9083 affects Lenovo System Management Module firmware versions prior to 1.06.
What can an attacker do with CVE-2018-9083?
An attacker can potentially log in to the device OS using weak default credentials if SSH or Telnet is enabled.
Is there a known exploit for CVE-2018-9083?
While there is no public exploit specifically noted for CVE-2018-9083, the vulnerability itself poses a significant security risk.