In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a debug log when user authentication fails.
Solution:
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://support.lenovo.com/us/en/solutions/LEN-24374 | vendor advisory |