In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.
Solution:
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://support.lenovo.com/us/en/solutions/LEN-24374 | vendor advisory |