LiveActive security incident?Get immediate response
CVE Record

CVE-2018-9068: The IMM2 First Failure Data Capture function collects management module logs and diagnostic information whe...

The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on the IMM2 management network interface. In versions earlier than 4.90 for Lenovo System x and earlier than 6.80 for IBM System x, the credentials to access the SFTP server are hard-coded and described in the IMM2 documentation, allowing an attacker with management network access to obtain the collected FFDC data. After applying the update, the IMM2 will create random SFTP credentials for use with OneCLI.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

Affected Lenovo and IBM System x IMM2 firmware used documented hard-coded SFTP credentials for FFDC diagnostic downloads. Anyone who can reach the IMM2 management network could retrieve collected hardware-error logs and diagnostic data. The sources describe data exposure, not system takeover, and the vendor update changes IMM2 to generate random SFTP credentials for OneCLI.

Executive priority

Treat this as a legacy management-plane data exposure issue. Prioritize environments where IMM2 is reachable beyond tightly controlled administration networks or where diagnostic logs could reveal sensitive infrastructure details. It is not KEV-listed, but unsupported or unpatched management controllers increase operational risk.

Technical view

IMM2 FFDC exposes collected management module logs through an SFTP service on the management interface. Firmware before Lenovo System x IMM2 4.90 and IBM System x IMM2 6.80 used static documented credentials. The documented remediation behavior is randomized SFTP credentials after update. No CVSS, CWE, or exploitation details are supplied in the bundle.

Likely exposure

Exposure is likely limited to organizations still operating legacy Lenovo System x IMM2 firmware below 4.90 or IBM System x IMM2 below 6.80, especially where management interfaces are reachable by broad admin, server, or VPN networks. Internet exposure is not stated in the sources.

Exploitation context

The bundle does not cite active exploitation, and CISA KEV status is false. Exploitation requires management network access and knowledge of the documented credentials. The available evidence supports unauthorized diagnostic data access, not remote code execution or service disruption.

Researcher notes

The public bundle lacks CVSS, CWE, detailed impact metrics, and exploit reports. Analysis should stay bounded to hard-coded documented SFTP credentials on IMM2 FFDC before the named firmware versions. Do not assume broader BMC compromise without additional vendor evidence.

Mitigation direction

  • Upgrade Lenovo System x IMM2 firmware to 4.90 or later.
  • Upgrade IBM System x IMM2 firmware to 6.80 or later.
  • Restrict IMM2 management interface access to trusted administration networks.
  • Review Lenovo advisory LEN-20227 for model-specific update guidance.
  • Check vendor guidance before applying operational workarounds.

Validation and detection

  • Inventory System x servers using IMM2 management modules.
  • Confirm IMM2 firmware versions against the affected thresholds.
  • Verify management interfaces are not broadly reachable.
  • Review access logs for unexpected FFDC SFTP activity, if available.
  • Confirm updated systems use randomized SFTP credentials for OneCLI.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-9068 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Lenovo Group Ltd.System x IMM2firmware versions earlier than 4.90Listed
IBM CorporationSystem x IMM2firmware versions earlier than 6.80Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.