VYPR
Critical severity9.8NVD Advisory· Published Apr 19, 2018· Updated Jun 17, 2026

CVE-2017-3774

CVE-2017-3774

Description

A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than version 4.70 used in some Lenovo servers and earlier than version 6.60 used in some IBM servers. An attacker providing a crafted user ID and password combination can cause a portion of the authentication routine to overflow its stack, resulting in stack corruption.

Affected products

2
  • IBM/IMM2v5
    Range: Earlier than 6.60
  • Lenovo/IMM2cpe-rescue
    Range: Earlier than 4.40

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.