{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T08:11:11.769","vulnerabilities":[{"cve":{"id":"CVE-2018-16089","sourceIdentifier":"psirt@lenovo.com","published":"2018-11-27T14:29:00.323","lastModified":"2026-06-17T01:43:42.273","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user."},{"lang":"es","value":"En System Management Module (SMM), en versiones anteriores a la 1.06, un campo en la cabecera de las imágenes de actualización del firmware de SMM no está lo suficientemente saneado, lo que permite una inyección de comandos tras la autenticación en el SMM como el usuario root."}],"affected":[{"source":"psirt@lenovo.com","affectedData":[{"vendor":"Lenovo","product":"ThinkSystem SMM","versions":[{"version":"unspecified","lessThan":"1.06","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":6.8,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:lenovo:system_management_module_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.06","matchCriteriaId":"9FD0EA83-B8E2-4C91-B32C-A8ED8A966974"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:lenovo:thinkagile_hx_enclosure_7x81:-:*:*:*:*:*:*:*","matchCriteriaId":"7CC0357A-E355-43CF-A3A0-FDBAC9579E24"},{"vulnerable":false,"criteria":"cpe:2.3:h:lenovo:thinkagile_hx_enclosure_7y87:-:*:*:*:*:*:*:*","matchCriteriaId":"97F59C97-615C-47A8-BA90-B1C70A10A0A9"},{"vulnerable":false,"criteria":"cpe:2.3:h:lenovo:thinkagile_hx_enclosure_7z02:-:*:*:*:*:*:*:*","matchCriteriaId":"84A63456-58CF-4640-97DE-C61A37036FFD"},{"vulnerable":false,"criteria":"cpe:2.3:h:lenovo:thinkagile_vx_enclosure_7y11:-:*:*:*:*:*:*:*","matchCriteriaId":"7E6AB649-A907-4B4D-A0F6-7E09619F6575"},{"vulnerable":false,"criteria":"cpe:2.3:h:lenovo:thinkagile_vx_enclosure_7y91:-:*:*:*:*:*:*:*","matchCriteriaId":"42A3257B-59D0-44D5-8B18-AABE9469F8F7"},{"vulnerable":false,"criteria":"cpe:2.3:h:lenovo:thinksystem_d2_enclosure_7x20:-:*:*:*:*:*:*:*","matchCriteriaId":"52EF5FF3-6312-4C6A-A09E-1921D039D626"},{"vulnerable":false,"criteria":"cpe:2.3:h:lenovo:thinksystem_modular_enclosure_7x22:-:*:*:*:*:*:*:*","matchCriteriaId":"E0FCCCB3-91FB-4EB8-8087-2E686EDBA78F"}]}]}],"references":[{"url":"https://support.lenovo.com/us/en/solutions/LEN-24374","source":"psirt@lenovo.com","tags":["Vendor Advisory"]},{"url":"https://support.lenovo.com/us/en/solutions/LEN-24374","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}