Project Subscriptions
| Vendors | Products |
|---|---|
|
Lenovo
Subscribe
|
Nextscale N1200 Enclosure
Subscribe
Nextscale N1200 Enclosure Firmware
Subscribe
Thinkagile Cp-cb-10
Subscribe
Thinkagile Cp-cb-10 Firmware
Subscribe
Thinkagile Cp-cb-10e
Subscribe
Thinkagile Cp-cb-10e Firmware
Subscribe
Thinkagile Hx Enclosure Certified Node
Subscribe
Thinkagile Hx Enclosure Certified Node Firmware
Subscribe
Thinkagile Vx Enclosure
Subscribe
Thinkagile Vx Enclosure Firmware
Subscribe
Thinksystem D2 Enclosure
Subscribe
Thinksystem D2 Enclosure Firmware
Subscribe
Thinksystem Da240 Enclosure
Subscribe
Thinksystem Da240 Enclosure Firmware
Subscribe
Thinksystem Dw612 Enclosure
Subscribe
Thinksystem Dw612 Enclosure Firmware
Subscribe
|
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-34429 | A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute. |
Solution
Upgrade to the firmware version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-127357 https://support.lenovo.com/us/en/product_security/LEN-127357
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-127357 |
|
Wed, 06 Nov 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-11-06T21:47:48.605Z
Reserved: 2023-05-30T16:27:50.393Z
Link: CVE-2023-2993
Updated: 2024-08-02T06:41:04.129Z
Status : Modified
Published: 2023-06-26T20:15:10.000
Modified: 2024-11-21T07:59:42.997
Link: CVE-2023-2993
No data.
OpenCVE Enrichment
No data.
EUVD