First published: Fri Nov 12 2021(Updated: )
A command injection vulnerability was reported in the Integrated Management Module (IMM) of legacy IBM System x 3550 M3 and IBM System x 3650 M3 servers that could allow the execution of operating system commands over an authenticated SSH or Telnet session.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo System X3550 M3 Firmware | ||
Lenovo System X3550 M3 Firmware | ||
Lenovo System X3650 M3 Firmware | ||
Lenovo System X3650 M3 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3723 is classified as a critical vulnerability due to the potential for command injection that could lead to remote code execution.
To fix CVE-2021-3723, update the firmware of the IBM System x 3550 M3 and IBM System x 3650 M3 servers to the latest version provided by IBM.
CVE-2021-3723 affects the IBM System x 3550 M3 and IBM System x 3650 M3 servers with vulnerable firmware.
Yes, CVE-2021-3723 can be exploited remotely through an authenticated SSH or Telnet session by an attacker.
The potential impact of CVE-2021-3723 includes unauthorized execution of operating system commands, which may lead to data breaches or further system compromise.