A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NLenovo Nextscale N1200 Enclosure
HWLenovoall versionsLenovo Nextscale N1200 Enclosure Firmware
OSLenovo< fhet60b-3.40Lenovo Thinkagile Cp Cb 10
HWLenovoall versionsLenovo Thinkagile Cp Cb 10e
HWLenovoall versionsLenovo Thinkagile Cp Cb 10e Firmware
OSLenovo< tesm38c-1.26Lenovo Thinkagile Cp Cb 10 Firmware
OSLenovo< tesm38c-1.26Lenovo Thinkagile Hx Enclosure Certified Node
HWLenovoall versionsLenovo Thinkagile Hx Enclosure Certified Node Firmware
OSLenovo< tesm38c-1.26Lenovo Thinkagile Vx Enclosure
HWLenovoall versionsLenovo Thinkagile Vx Enclosure Firmware
OSLenovo< tesm38c-1.26Lenovo Thinksystem D2 Enclosure
HWLenovoall versionsLenovo Thinksystem D2 Enclosure Firmware
OSLenovo< tesm38c-1.26Lenovo Thinksystem Da240 Enclosure
HWLenovoall versionsLenovo Thinksystem Da240 Enclosure Firmware
OSLenovo< umsm10s-1.07Lenovo Thinksystem Dw612 Enclosure
HWLenovoall versionsLenovo Thinksystem Dw612 Enclosure Firmware
OSLenovo< umsm10s-1.07
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2021-3849CRITICAL9.8PL ✓same product
Auth Bypass w firmware Lenovo FPC2 i SMM — zdalne wykonanie poleceń
CVE-2021-3897CRITICAL9.8PL ✓same product
Auth Bypass w firmware Lenovo FPC2 i SMM — nieautoryzowane wykonanie poleceń
CVE-2024-2659HIGH7.2same product
A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user w...
CVE-2023-2992HIGH7.5same product
An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web serve...
CVE-2022-34884HIGH7.2same product
A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated use...