VYPR

Thinkserver Rd440 Firmware

by Lenovo

CVEs (3)

  • CVE-2017-17833CriApr 23, 2018
    risk 0.64cvss 9.8epss 0.04

    OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.

  • CVE-2018-9086HigNov 16, 2018
    risk 0.47cvss 7.2epss 0.02

    In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged user to download and execute arbitrary code inside the BMC. This can only be exploited by authorized privileged users.

  • CVE-2017-3753MedAug 10, 2017
    risk 0.44cvss 6.8epss 0.01

    A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run…