CVE-2018-9085: Missing System x Flash Memory Write Protection Lock Bit
A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9085?
The severity of CVE-2018-9085 is rated as high because it allows an attacker with administrative access to modify critical flash memory settings.
How do I fix CVE-2018-9085?
To fix CVE-2018-9085, ensure that you update the firmware to the latest version that sets the write protection lock bit correctly after boot.
What systems are affected by CVE-2018-9085?
CVE-2018-9085 affects older generation Lenovo and IBM System x servers, including configurations of the Flex System, System X3750, and BladeCenter series.
Who is vulnerable to CVE-2018-9085?
Any organization using the affected Lenovo and IBM servers with the specified firmware versions is vulnerable to CVE-2018-9085.
Is CVE-2018-9085 reversible once exploited?
Once exploited, the changes made by an attacker to the flash memory may not be easily reversible, depending on the modifications made.