CVE-2017-3774: Lenovo Integrated Management Module 2
Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.
A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than version 4.70 used in some Lenovo servers and earlier than version 6.60 used in some IBM servers. An attacker providing a crafted user ID and password combination can cause a portion of the authentication routine to overflow its stack, resulting in stack corruption.
Affected products
- Lenovo Integrated Management Module 2: before 4.70 (fixed in 4.70); before 6.60 (fixed in 6.60)
Published 2018-04-19. Last modified 2026-06-17.