6.3
CVSSv3

CVE-2023-2993

Published: 26/06/2023 Updated: 05/07/2023
CVSS v3 Base Score: 6.3 | Impact Score: 3.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute.

Vulnerable Product Search on Vulmon Subscribe to Product

lenovo nextscale n1200 enclosure firmware

lenovo thinkagile cp-cb-10 firmware

lenovo thinkagile cp-cb-10e firmware

lenovo thinkagile hx enclosure certified node firmware

lenovo thinkagile vx enclosure firmware

lenovo thinksystem d2 enclosure firmware

lenovo thinksystem da240 enclosure firmware

lenovo thinksystem dw612 enclosure firmware