Vulnerability Description
An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions. Rebooting SMM or FPC will restore access to the management web server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Nextscale N1200 Enclosure Firmware | < fhet60b-3.40 |
| Lenovo | Nextscale N1200 Enclosure | - |
| Lenovo | Thinkagile Cp-Cb-10 Firmware | < tesm38c-1.26 |
| Lenovo | Thinkagile Cp-Cb-10 | - |
| Lenovo | Thinkagile Cp-Cb-10E Firmware | < tesm38c-1.26 |
| Lenovo | Thinkagile Cp-Cb-10E | - |
| Lenovo | Thinkagile Hx Enclosure Certified Node Firmware | < tesm38c-1.26 |
| Lenovo | Thinkagile Hx Enclosure Certified Node | - |
| Lenovo | Thinkagile Vx Enclosure Firmware | < tesm38c-1.26 |
| Lenovo | Thinkagile Vx Enclosure | - |
| Lenovo | Thinksystem D2 Enclosure Firmware | < tesm38c-1.26 |
| Lenovo | Thinksystem D2 Enclosure | - |
| Lenovo | Thinksystem Da240 Enclosure Firmware | < umsm10s-1.07 |
| Lenovo | Thinksystem Da240 Enclosure | - |
| Lenovo | Thinksystem Dw612 Enclosure Firmware | < umsm10s-1.07 |
| Lenovo | Thinksystem Dw612 Enclosure | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/LEN-127357Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-127357Vendor Advisory
FAQ
What is CVE-2023-2992?
CVE-2023-2992 is a vulnerability with a CVSS score of 7.5 (HIGH). An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions. Rebooting SMM or FPC will restore acce...
How severe is CVE-2023-2992?
CVE-2023-2992 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-2992?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Nextscale N1200 Enclosure Firmware, Lenovo Nextscale N1200 Enclosure, Lenovo Thinkagile Cp-Cb-10 Firmware, Lenovo Thinkagile Cp-Cb-10, Lenovo Thinkagile Cp-Cb-10E Firmware.