Show filters
34 Total Results
Displaying 31-34 of 34
Sort by:
Attacker Value
Unknown
CVE-2017-2751
Disclosure Date: October 03, 2018 (last updated November 27, 2024)
A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consumer notebooks launched in early 2014.
0
Attacker Value
Unknown
CVE-2018-9068
Disclosure Date: July 26, 2018 (last updated November 27, 2024)
The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on the IMM2 management network interface. In versions earlier than 4.90 for Lenovo System x and earlier than 6.80 for IBM System x, the credentials to access the SFTP server are hard-coded and described in the IMM2 documentation, allowing an attacker with management network access to obtain the collected FFDC data. After applying the update, the IMM2 will create random SFTP credentials for use with OneCLI.
0
Attacker Value
Unknown
CVE-2017-3768
Disclosure Date: January 26, 2018 (last updated November 26, 2024)
An unprivileged attacker with connectivity to the IMM2 could cause a denial of service attack on the IMM2 (Versions earlier than 4.4 for Lenovo System x and earlier than 6.4 for IBM System x). Flooding the IMM2 with a high volume of authentication failures via the Common Information Model (CIM) used by LXCA and OneCLI and other tools can exhaust available system memory which can cause the IMM2 to reboot itself until the requests cease.
0
Attacker Value
Unknown
CVE-2015-2886
Disclosure Date: April 10, 2017 (last updated November 26, 2024)
iBaby M6 allows remote attackers to obtain sensitive information, related to the ibabycloud.com service.
0