CVE-2018-9083: Lenovo System Management Module Firmware

High severity, CVSS 8.1. EPSS: 1.1% chance of exploitation in the next 30 days.

In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.

Affected products

  • Lenovo System Management Module Firmware: before 1.06 (fixed in 1.06)

Published 2018-11-27. Last modified 2026-06-17.