CVE-2018-9086: Legacy Server BMC Remote Command Injection
In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged user to download and execute arbitrary code inside the BMC. This can only be exploited by authorized privileged users.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9086?
The severity of CVE-2018-9086 is high with a severity value of 7.2.
How does the command injection vulnerability in CVE-2018-9086 work?
The command injection vulnerability in CVE-2018-9086 allows a privileged user to download and execute arbitrary code inside the BMC firmware download command.
Who can exploit the command injection vulnerability in CVE-2018-9086?
Only authorized privileged users can exploit the command injection vulnerability in CVE-2018-9086.
Which Lenovo ThinkServer-branded servers are affected by CVE-2018-9086?
Lenovo ThinkServer RD340, RD440, RD640, and TD340 firmware versions up to exclusive 64.00 are affected by CVE-2018-9086.
How can I fix the command injection vulnerability in CVE-2018-9086?
To fix the command injection vulnerability in CVE-2018-9086, update the BMC firmware to a version that is not vulnerable.