HIGH · 7.5

CVE-2023-2992

An unauthenticated  denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions. Rebooting SMM or FPC will restore acce...

Vulnerability Description

An unauthenticated  denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions. Rebooting SMM or FPC will restore access to the management web server.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
LenovoNextscale N1200 Enclosure Firmware< fhet60b-3.40
LenovoNextscale N1200 Enclosure-
LenovoThinkagile Cp-Cb-10 Firmware< tesm38c-1.26
LenovoThinkagile Cp-Cb-10-
LenovoThinkagile Cp-Cb-10E Firmware< tesm38c-1.26
LenovoThinkagile Cp-Cb-10E-
LenovoThinkagile Hx Enclosure Certified Node Firmware< tesm38c-1.26
LenovoThinkagile Hx Enclosure Certified Node-
LenovoThinkagile Vx Enclosure Firmware< tesm38c-1.26
LenovoThinkagile Vx Enclosure-
LenovoThinksystem D2 Enclosure Firmware< tesm38c-1.26
LenovoThinksystem D2 Enclosure-
LenovoThinksystem Da240 Enclosure Firmware< umsm10s-1.07
LenovoThinksystem Da240 Enclosure-
LenovoThinksystem Dw612 Enclosure Firmware< umsm10s-1.07
LenovoThinksystem Dw612 Enclosure-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-2992?

CVE-2023-2992 is a vulnerability with a CVSS score of 7.5 (HIGH). An unauthenticated  denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions. Rebooting SMM or FPC will restore acce...

How severe is CVE-2023-2992?

CVE-2023-2992 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-2992?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Nextscale N1200 Enclosure Firmware, Lenovo Nextscale N1200 Enclosure, Lenovo Thinkagile Cp-Cb-10 Firmware, Lenovo Thinkagile Cp-Cb-10, Lenovo Thinkagile Cp-Cb-10E Firmware.