Medium severity4.9NVD Advisory· Published Nov 16, 2018· Updated Jun 17, 2026
CVE-2018-9085
CVE-2018-9085
Description
A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.
Affected products
32- cpe:2.3:o:ibm:bladecenter_hs23e_firmware:*:*:*:*:*:*:*:*Range: <ahe160c
- cpe:2.3:o:ibm:flex_system_x220_m4_firmware:*:*:*:*:*:*:*:*Range: <kse158c
- cpe:2.3:o:ibm:flex_system_x222_m4_firmware:*:*:*:*:*:*:*:*Range: <cce160c
- cpe:2.3:o:ibm:flex_system_x240_m4_firmware:*:*:*:*:*:*:*:*Range: <ahe160c
- cpe:2.3:o:ibm:flex_system_x280_x6_firmware:*:*:*:*:*:*:*:*Range: <n3e132w
- cpe:2.3:o:ibm:flex_system_x440_m4_firmware:*:*:*:*:*:*:*:*Range: <cne162d
- cpe:2.3:o:ibm:flex_system_x480_x6_firmware:*:*:*:*:*:*:*:*Range: <n3e132w
- cpe:2.3:o:ibm:flex_system_x880_x6_firmware:*:*:*:*:*:*:*:*Range: <n2e130e
- cpe:2.3:o:ibm:idataplex_dx360_m4_firmware:*:*:*:*:*:*:*:*Range: <fhe120d
- cpe:2.3:o:ibm:idataplex_dx360_m4_water_cooled_firmware:*:*:*:*:*:*:*:*Range: <fhe120d
- cpe:2.3:o:ibm:system_x3650_m4_bd_firmware:*:*:*:*:*:*:*:*Range: <vve160c
- cpe:2.3:o:ibm:system_x3650_m4_hd_firmware:*:*:*:*:*:*:*:*Range: <vve160c
- cpe:2.3:o:lenovo:flex_system_x240_m4_firmware:*:*:*:*:*:*:*:*Range: <a3e122b
- cpe:2.3:o:lenovo:flex_system_x440_m4_firmware:*:*:*:*:*:*:*:*Range: <cge122b
- cpe:2.3:o:lenovo:system_x3750_m4_firmware:*:*:*:*:*:*:*:*Range: <a5e124b
- IBM/System x UEFIv5Range: unspecified
Patches
Vulnerability mechanics
References
1- support.lenovo.com/us/en/solutions/LEN-24477nvdVendor Advisory
News mentions
0No linked articles in our index yet.