VYPR
Medium severity4.9NVD Advisory· Published Nov 16, 2018· Updated Jun 17, 2026

CVE-2018-9085

CVE-2018-9085

Description

A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.

Affected products

32

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.