CVE-2017-3774
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
19/04/2018
Last modified:
24/05/2018
Description
A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than version 4.70 used in some Lenovo servers and earlier than version 6.60 used in some IBM servers. An attacker providing a crafted user ID and password combination can cause a portion of the authentication routine to overflow its stack, resulting in stack corruption.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:lenovo:integrated_management_module_2:*:*:*:*:*:*:*:* | 4.70 (excluding) | |
| cpe:2.3:h:lenovo:flex_system_x240_m4:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:flex_system_x240_m5:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:flex_system_x280_x6:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:flex_system_x440_m4:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:flex_system_x480_x6:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:flex_system_x880:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:nextscale_nx360_m5:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:system_x3250_m6:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:system_x3500_m5:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:system_x3550_m5:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:system_x3650_m5:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:system_x3750_m4:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:system_x3850_x6:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:system_x3950_x6:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



