CRITICAL🇵🇱 Wersja polska

CVE-2021-3897

CVSS 9.8v3.1pub. 2022-04-22upd. 2024-11-21

An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware during an that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not affected.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • IBM Nextscale Fan Power Controller

    HW
    Ibm
    all versions
  • IBM Nextscale Fan Power Controller Firmware

    OS
    Ibm
    < 44a-3.70
  • Lenovo Nextscale N1200 Enclosure

    HW
    Lenovo
    all versions
  • Lenovo Nextscale N1200 Enclosure Firmware

    OS
    Lenovo
    < fhet50b-2.90
  • Lenovo Thinkagile Hx Enclosure Certified Node

    HW
    Lenovo
    all versions
  • Lenovo Thinkagile Hx Enclosure Certified Node Firmware

    OS
    Lenovo
    < tesm28b-1.21
  • Lenovo Thinkagile Vx Enclosure

    HW
    Lenovo
    all versions
  • Lenovo Thinkagile Vx Enclosure Firmware

    OS
    Lenovo
    < tesm28b-1.21
  • Lenovo Thinksystem D2 Enclosure

    HW
    Lenovo
    all versions
  • Lenovo Thinksystem D2 Enclosure Firmware

    OS
    Lenovo
    < tesm28b-1.21
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2021-3849CRITICAL9.8PL ✓same product

Auth Bypass w firmware Lenovo FPC2 i SMM — zdalne wykonanie poleceń

CVE-2024-2659HIGH7.2same product

A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user w...

CVE-2023-2992HIGH7.5same product

An unauthenticated  denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web serve...

CVE-2022-34884HIGH7.2same product

A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated use...

CVE-2023-2993MEDIUM5.4same product

A valid, authenticated user with limited privileges may be able to use specifically crafted web management ser...