9.8
CVSSv3

CVE-2021-3849

Published: 22/04/2022 Updated: 27/10/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An authentication bypass vulnerability exists in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware that could allow an unauthenticated malicious user to execute commands on the SMM and FPC2. SMM2 is not affected.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lenovo nextscale_n1200_enclosure_firmware

lenovo thinkagile_hx_enclosure_certified_node_firmware

lenovo thinkagile_vx_enclosure_firmware

lenovo thinksystem_d2_enclosure_firmware

ibm nextscale_fan_power_controller_firmware