ID

VAR-201904-0097


CVE

CVE-2019-6155


TITLE

IBM System x and BladeCenter System input validation vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2019-004353

DESCRIPTION

A potential vulnerability was found in an SMI handler in various BIOS versions of certain legacy IBM System x and IBM BladeCenter systems that could lead to denial of service. IBM System x and BladeCenter There is an input validation vulnerability in the system.Service operation interruption (DoS) There is a possibility of being put into a state. The vulnerability stems from the failure of the network system or product to properly validate the input data. The following products and versions are affected: IBM BladeCenter HS23E; System x3530 M4; System x3630 M4; System x3650 M4 BD

Trust: 1.71

sources: NVD: CVE-2019-6155 // JVNDB: JVNDB-2019-004353 // VULHUB: VHN-157590

AFFECTED PRODUCTS

vendor:ibmmodel:system x3530 m4scope:ltversion:3.20

Trust: 1.0

vendor:ibmmodel:bladecenter hs23scope:ltversion:3.0.0

Trust: 1.0

vendor:ibmmodel:system x3650 m4 hdscope:ltversion:2.40

Trust: 1.0

vendor:ibmmodel:system x3630 m4scope:ltversion:3.20

Trust: 1.0

vendor:ibmmodel:bladecenter hs23scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3530 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3630 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3650 m4 bdscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2019-004353 // NVD: CVE-2019-6155

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-6155
value: HIGH

Trust: 1.0

psirt@lenovo.com: CVE-2019-6155
value: MEDIUM

Trust: 1.0

NVD: CVE-2019-6155
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201904-945
value: MEDIUM

Trust: 0.6

VULHUB: VHN-157590
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2019-6155
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-157590
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-6155
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

psirt@lenovo.com: CVE-2019-6155
baseSeverity: MEDIUM
baseScore: 4.1
vectorString: CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
attackVector: LOCAL
attackComplexity: HIGH
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 0.5
impactScore: 3.6
version: 3.0

Trust: 1.0

sources: VULHUB: VHN-157590 // JVNDB: JVNDB-2019-004353 // CNNVD: CNNVD-201904-945 // NVD: CVE-2019-6155 // NVD: CVE-2019-6155

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-20

Trust: 0.9

sources: VULHUB: VHN-157590 // JVNDB: JVNDB-2019-004353 // NVD: CVE-2019-6155

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201904-945

TYPE

input validation error

Trust: 0.6

sources: CNNVD: CNNVD-201904-945

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-004353

PATCH

title:トップページurl:https://www.ibm.com/jp-ja/index-h.html

Trust: 0.8

title:LEN-25165url:https://support.lenovo.com/jp/ja/solutions/len-25165

Trust: 0.8

title:IBM System x and IBM BladeCenter system SMI handler Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=91765

Trust: 0.6

sources: JVNDB: JVNDB-2019-004353 // CNNVD: CNNVD-201904-945

EXTERNAL IDS

db:NVDid:CVE-2019-6155

Trust: 2.5

db:LENOVOid:LEN-25165

Trust: 1.7

db:JVNDBid:JVNDB-2019-004353

Trust: 0.8

db:CNNVDid:CNNVD-201904-945

Trust: 0.7

db:AUSCERTid:ESB-2019.1525

Trust: 0.6

db:VULHUBid:VHN-157590

Trust: 0.1

sources: VULHUB: VHN-157590 // JVNDB: JVNDB-2019-004353 // CNNVD: CNNVD-201904-945 // NVD: CVE-2019-6155

REFERENCES

url:https://support.lenovo.com/solutions/len-25165

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2019-6155

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-6155

Trust: 0.8

url:https://support.lenovo.com/us/en/solutions/len-25165

Trust: 0.6

url:https://www-01.ibm.com/support/docview.wss?uid=ibm10883170

Trust: 0.6

url:https://www.auscert.org.au/bulletins/80134

Trust: 0.6

sources: VULHUB: VHN-157590 // JVNDB: JVNDB-2019-004353 // CNNVD: CNNVD-201904-945 // NVD: CVE-2019-6155

SOURCES

db:VULHUBid:VHN-157590
db:JVNDBid:JVNDB-2019-004353
db:CNNVDid:CNNVD-201904-945
db:NVDid:CVE-2019-6155

LAST UPDATE DATE

2024-11-23T22:58:45.594000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-157590date:2020-08-24T00:00:00
db:JVNDBid:JVNDB-2019-004353date:2019-05-31T00:00:00
db:CNNVDid:CNNVD-201904-945date:2020-10-22T00:00:00
db:NVDid:CVE-2019-6155date:2024-11-21T04:46:02.453

SOURCES RELEASE DATE

db:VULHUBid:VHN-157590date:2019-04-22T00:00:00
db:JVNDBid:JVNDB-2019-004353date:2019-05-31T00:00:00
db:CNNVDid:CNNVD-201904-945date:2019-04-19T00:00:00
db:NVDid:CVE-2019-6155date:2019-04-22T16:29:01.973