Database/Control plane, storage & DevOps
Lenovo / IBM Integrated Management Module 2 (IMM2) web administration service: The overflow is inside the
Impact
The overflow is inside the authentication routine itself, so a crafted user ID and password pair corrupts the BMC's stack before any credential decision is made - no account needed. Successful exploitation is control of the management controller: power state, virtual media, host firmware, serial console. The pattern is worth naming for anyone building a BMC risk model, because it recurs across vendors and a decade: the code that parses the login attempt is the least-privileged-input, highest-privilege-context code on the device, and it is repeatedly written in C against fixed buffers. Same shape as the Supermicro login.cgi overflow four years earlier.
Who can reach it
Network, pre-auth. Any reachability to the IMM2 web administration service.
What to do
Flash IMM2 firmware to 4.70+ (Lenovo-branded servers) or 6.60+ (IBM-branded). Out-of-band update, node drain not strictly required but advisable since the IMM restarts. As with every pre-auth BMC bug in this catalogue, the flash is the fix and network isolation is the control that makes the flash schedulable rather than an emergency: if the BMC is only reachable from a bastion, an unpatched pre-auth overflow is a risk you can plan around; if it is reachable from a tenant VLAN or the internet, it is not.
References
Related entries
- Intel Active Management Technology / Standard Manageability: An authentication bypass in the AMT web interface: sendingCVE-2017-5689 · Intel Active Management Technology / Standard ManageabilityCritical
- HPE iLO2: Authentication bypass and code execution in iLO2 firmware 2.29CVE-2017-8979 · HPE iLO2Critical
- ntpq / ntpdc (NTP 4.2.8p11 client utilities): Stack buffer overflow in the ntpq and ntpdc command-line tools via a longCVE-2018-12327 · ntpq / ntpdc (NTP 4.2.8p11 client utilities)Critical
- Ceph iSCSI gateway (ceph-iscsi-cli / rbd-target-api): rbd-target-api ships with the Werkzeug debug console enabledCVE-2018-14649 · Ceph iSCSI gateway (ceph-iscsi-cli / rbd-target-api)Critical
- Raritan CommandCenter Secure Gateway (CC-SG), before 8.0.0: CC-SG is Raritan's single-pane-of-glass gateway thatCVE-2018-20687 · Raritan CommandCenter Secure Gateway (CC-SG), before 8.0.0Critical
- Slurm (slurmdbd accounting database daemon): SQL injection into SlurmDBD gives an attacker read and write control ofCVE-2018-7033 · Slurm (slurmdbd accounting database daemon)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.