PT-2018-7264 · Lenovo+1 · Lenovo System X+1
Publicado
2018-01-26
·
Atualizado
2018-02-15
·
CVE-2017-3768
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
Lenovo System x versions prior to 4.4
IBM System x versions prior to 6.4
Description:
The issue allows an unprivileged attacker with connectivity to the IMM2 to cause a denial of service attack. This can be achieved by flooding the IMM2 with a high volume of authentication failures via the Common Information Model (CIM) used by tools such as LXCA and OneCLI. The attack exhausts available system memory, causing the IMM2 to reboot itself until the requests cease.
Recommendations:
For Lenovo System x versions prior to 4.4, update to version 4.4 or later to resolve the issue.
For IBM System x versions prior to 6.4, update to version 6.4 or later to resolve the issue.
Correção
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm System X
Lenovo System X