First published: Fri Nov 16 2018(Updated: )
A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Flex System X240 M4 | <a3e122b | |
Lenovo Flex System X240 M4 Firmware | ||
Ibm Flex System X440 M4 Firmware | <cge122b | |
Lenovo Flex System X440 M4 Firmware | ||
Lenovo System X3750 M4 | <a5e124b | |
Lenovo System X3750 M4 | ||
Lenovo Bladecenter Hs23 Firmware | <tke160c | |
IBM BladeCenter | =hs23 | |
Lenovo Bladecenter Hs23e Firmware | <ahe160c | |
IBM BladeCenter | =hs23e | |
IBM Flex System X220 M4 | <kse158c | |
Lenovo Flex System X220 | ||
IBM Flex System X222 M4 Firmware | <cce160c | |
IBM Flex System X222 M4 Firmware | ||
Lenovo Flex System X240 M4 | <ahe160c | |
Lenovo Flex System X240 M4 | ||
Lenovo Flex System X280 X6 | <n3e132w | |
Lenovo Flex System X280 X6 | ||
Lenovo Flex System X440 M4 | <cne162d | |
Lenovo Flex System X440 M4 Firmware | ||
Lenovo Flex System X480 X6 Firmware | <n3e132w | |
Lenovo Flex System X480 X6 Firmware | ||
Lenovo Flex System X880 Firmware | <n2e130e | |
Lenovo Flex System X880 X6 Bios | ||
Lenovo iDataplex DX360 M4 Firmware | <fhe120d | |
Lenovo iDataplex Dx360 M4 | ||
Lenovo Idataplex Dx360 M4 Water Cooled Firmware | <fhe120d | |
Ibm System X3100 M4 Firmware | <jqe184c | |
Ibm System X3100 M4 Firmware | ||
IBM System X3100 M5 Firmware | <j9e134c | |
IBM System X3100 M5 Firmware | ||
IBM System X3250 M4 Firmware | <jqe184c | |
IBM System X3250 M4 Firmware | ||
Ibm System X3250 M5 Firmware | <jue134c | |
Lenovo System X3250 M5 | ||
Lenovo System X3300 M4 Firmware | <yae156c | |
Lenovo System X3300 M4 | ||
IBM System x3500 M4 | <y5e158c | |
Lenovo System X3500 M4 Firmware | ||
Lenovo System X3530 M4 Firmware | <bee164c | |
Lenovo System X3530 M4 | ||
Lenovo System X3550 M4 Firmware | <d7e166d | |
Lenovo System X3550 M4 | ||
Lenovo System X3630 M4 Firmware | <vve162c | |
Lenovo System X3630 M4 | ||
IBM System X3650 M4 Bd Firmware | <vve160c | |
IBM System x3650 M4 Firmware | ||
Lenovo System X3650 M4 Firmware | <vve160c | |
IBM System x3650 M4 Firmware | ||
Lenovo System X3650 M4 Firmware | <vve160c | |
Lenovo System X3650 M4 HD | ||
Lenovo System X3750 M4 Firmware | <koe160c | |
Lenovo System X3750 M4 | ||
Lenovo System X3850 X6 Firmware | <a8e128c | |
Lenovo System X3850 X6 Firmware | ||
Lenovo System X3950 X6 Firmware | <bee164c | |
Lenovo System X3950 X6 Firmware |
Update UEFI firmware
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-9085 is rated as high because it allows an attacker with administrative access to modify critical flash memory settings.
To fix CVE-2018-9085, ensure that you update the firmware to the latest version that sets the write protection lock bit correctly after boot.
CVE-2018-9085 affects older generation Lenovo and IBM System x servers, including configurations of the Flex System, System X3750, and BladeCenter series.
Any organization using the affected Lenovo and IBM servers with the specified firmware versions is vulnerable to CVE-2018-9085.
Once exploited, the changes made by an attacker to the flash memory may not be easily reversible, depending on the modifications made.