CVE-2018-9073: Lenovo Chassis Management Module Firmware

Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.

Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets.

Affected products

  • Lenovo Chassis Management Module Firmware: before 2.0.0 (fixed in 2.0.0)

Published 2018-11-16. Last modified 2026-06-17.