An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions. Rebooting SMM or FPC will restore access to the management web server.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Lenovo
Subscribe
|
Nextscale N1200 Enclosure
Subscribe
Nextscale N1200 Enclosure Firmware
Subscribe
Thinkagile Cp-cb-10
Subscribe
Thinkagile Cp-cb-10 Firmware
Subscribe
Thinkagile Cp-cb-10e
Subscribe
Thinkagile Cp-cb-10e Firmware
Subscribe
Thinkagile Hx Enclosure Certified Node
Subscribe
Thinkagile Hx Enclosure Certified Node Firmware
Subscribe
Thinkagile Vx Enclosure
Subscribe
Thinkagile Vx Enclosure Firmware
Subscribe
Thinksystem D2 Enclosure
Subscribe
Thinksystem D2 Enclosure Firmware
Subscribe
Thinksystem Da240 Enclosure
Subscribe
Thinksystem Da240 Enclosure Firmware
Subscribe
Thinksystem Dw612 Enclosure
Subscribe
Thinksystem Dw612 Enclosure Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-34428 | An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions. Rebooting SMM or FPC will restore access to the management web server. |
Fixes
Solution
Upgrade to the firmware version (or newer) indicated for your model in the Lenovo Product Security: https://support.lenovo.com/us/en/product_security/LEN-127357
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-127357 |
|
History
Mon, 16 Sep 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 |
Mon, 16 Sep 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-405 |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-09-16T14:51:34.588Z
Reserved: 2023-05-30T16:27:48.220Z
Link: CVE-2023-2992
Updated: 2024-08-02T06:41:04.131Z
Status : Modified
Published: 2023-06-26T20:15:09.933
Modified: 2024-11-21T07:59:42.850
Link: CVE-2023-2992
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD