CVE-2017-3744 Vulnerability Details

  /     /     /  

CVE-2017-3744 Metadata Quick Info

CVE Published: 20/06/2017 | CVE Updated: 05/08/2024 | CVE Year: 2017
Source: lenovo | Vendor: Lenovo Group Ltd. | Product: Lenovo System x IMM2
Status : PUBLISHED

CVE-2017-3744 Description

In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command data may contain clear text login information. Authorized users that can capture and export FFDC service log data may have access to these remote commands.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Disclosure of login credentials to user with local privileges
Source: Lenovo Group Ltd.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).