Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information related to the current authentication configuration settings. Exposed settings relate to password lengths, expiration, and lockout configuration.
References
Link Resource
https://support.lenovo.com/us/en/solutions/LEN-23806 Mitigation Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: lenovo

Published: 2018-11-16T14:00:00

Updated: 2018-11-16T13:57:01

Reserved: 2018-03-27T00:00:00


Link: CVE-2018-9071

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-11-16T14:29:00.347

Modified: 2018-12-20T21:06:57.820


Link: CVE-2018-9071

JSON object: View

cve-icon Redhat Information

No data.

CWE