Lucene search

K
lenovoLenovoLENOVO:PS500241-NOSID
HistoryMay 02, 2019 - 1:16 p.m.

ASPEED AST-series BMC Vulnerability - US

2019-05-0213:16:51
support.lenovo.com
84

0.003 Low

EPSS

Percentile

70.6%

Lenovo Security Advisory: LEN-26252

Potential Impact: Privilege escalation

Severity: High

Scope of Impact: Industry-wide

CVE Identifier: CVE-2019-6260

Summary Description:

An industry-wide vulnerability affecting ASPEED AST-series Baseboard Management Controllers (BMCs) used in certain servers and storage devices can allow arbitrary read and write access to the BMC’s physical address space from the host. ThinkSystem and System x servers are not affected.

Mitigation Strategy for Customers (what you should do to protect yourself):

Upgrade to the firmware version (or newer) indicated for your model in the Product Impact section below.


Product Impact:

0.003 Low

EPSS

Percentile

70.6%