CVE-2017-3774 Details
Description
A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than version 4.70 used in some Lenovo servers and earlier than version 6.60 used in some IBM servers. An attacker providing a crafted user ID and password combination can cause a portion of the authentication routine to overflow its stack, resulting in stack corruption.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-19586 | CVE | Vendor Advisory |
| https://support.lenovo.com/us/en/product_security/LEN-19586 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lenovo integrated management module 2 | < 4.70 < 6.60 |
CPE
Remediation
| |
| lenovo flex system x240 m4 | All versions |
CPE
Remediation
| |
| lenovo flex system x240 m5 | All versions |
CPE
Remediation
| |
| lenovo flex system x280 x6 | All versions |
CPE
Remediation
| |
| lenovo flex system x440 m4 | All versions |
CPE
Remediation
| |
| lenovo flex system x480 x6 | All versions |
CPE
Remediation
| |
| lenovo flex system x880 | All versions |
CPE
Remediation
| |
| lenovo nextscale nx360 m5 | All versions |
CPE
Remediation
| |
| lenovo system x3250 m6 | All versions |
CPE
Remediation
| |
| lenovo system x3500 m5 | All versions |
CPE
Remediation
| |
| lenovo system x3550 m5 | All versions |
CPE
Remediation
| |
| lenovo system x3650 m5 | All versions |
CPE
Remediation
| |
| lenovo system x3750 m4 | All versions |
CPE
Remediation
| |
| lenovo system x3850 x6 | All versions |
CPE
Remediation
| |
| lenovo system x3950 x6 | All versions |
CPE
Remediation
| |
| ibm bladecenter hs22 | All versions |
CPE
Remediation
| |
| ibm bladecenter hs23 | All versions |
CPE
Remediation
| |
| ibm bladecenter hs23e | All versions |
CPE
Remediation
| |
| ibm flex system x220 m4 | All versions |
CPE
Remediation
| |
| ibm flex system x222 m4 | All versions |
CPE
Remediation
| |
| ibm flex system x240 m4 | All versions |
CPE
Remediation
| |
| ibm flex system x280 m4 | All versions |
CPE
Remediation
| |
| ibm flex system x440 m4 | All versions |
CPE
Remediation
| |
| ibm flex system x480 m4 | All versions |
CPE
Remediation
| |
| ibm flex system x880 m4 | All versions |
CPE
Remediation
| |
| ibm idataplex dx360 m4 | All versions |
CPE
Remediation
| |
| ibm idataplex dx360 m4 water cooled | All versions |
CPE
Remediation
| |
| ibm nextscale nx360 m4 | All versions |
CPE
Remediation
| |
| ibm system x3100 m4 | All versions |
CPE
Remediation
| |
| ibm system x3100 m5 | All versions |
CPE
Remediation
| |
| ibm system x3250 m4 | All versions |
CPE
Remediation
| |
| ibm system x3250 m5 | All versions |
CPE
Remediation
| |
| ibm system x3300 m4 | All versions |
CPE
Remediation
| |
| ibm system x3500 m4 | All versions |
CPE
Remediation
| |
| ibm system x3530 m4 | All versions |
CPE
Remediation
| |
| ibm system x3550 m4 | All versions |
CPE
Remediation
| |
| ibm system x3630 m4 | All versions |
CPE
Remediation
| |
| ibm system x3650 m4 | All versions |
CPE
Remediation
| |
| ibm system x3650 m4 bd | All versions |
CPE
Remediation
| |
| ibm system x3650 m4 hd | All versions |
CPE
Remediation
| |
| ibm system x3750 m4 | All versions |
CPE
Remediation
| |
| ibm system x3850 x6 | All versions |
CPE
Remediation
| |
| ibm system x3950 x6 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| May 24, 2018 | Initial Analysis | [email protected] |