First published: Mon Jun 26 2023(Updated: )
An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions. Rebooting SMM or FPC will restore access to the management web server.
Credit: psirt@lenovo.com psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Nextscale N1200 Enclosure Firmware | <fhet60b-3.40 | |
Lenovo Nextscale N1200 Enclosure | ||
Lenovo Thinkagile Cp-cb-10 Firmware | <tesm38c-1.26 | |
Lenovo Thinkagile Cp-cb-10 | ||
Lenovo Thinkagile Cp-cb-10e Firmware | <tesm38c-1.26 | |
Lenovo Thinkagile Cp-cb-10e | ||
Lenovo Thinkagile Hx Enclosure Certified Node Firmware | <tesm38c-1.26 | |
Lenovo Thinkagile Hx Enclosure Certified Node | ||
Lenovo Thinkagile Vx Enclosure Firmware | <tesm38c-1.26 | |
Lenovo Thinkagile Vx Enclosure | ||
Lenovo Thinksystem D2 Enclosure Firmware | <tesm38c-1.26 | |
Lenovo Thinksystem D2 Enclosure | ||
Lenovo Thinksystem Da240 Enclosure Firmware | <umsm10s-1.07 | |
Lenovo Thinksystem Da240 Enclosure | ||
Lenovo Thinksystem Dw612 Enclosure Firmware | <umsm10s-1.07 | |
Lenovo Thinksystem Dw612 Enclosure | ||
All of | ||
Lenovo Nextscale N1200 Enclosure Firmware | <fhet60b-3.40 | |
Lenovo Nextscale N1200 Enclosure | ||
All of | ||
Lenovo Thinkagile Cp-cb-10 Firmware | <tesm38c-1.26 | |
Lenovo Thinkagile Cp-cb-10 | ||
All of | ||
Lenovo Thinkagile Cp-cb-10e Firmware | <tesm38c-1.26 | |
Lenovo Thinkagile Cp-cb-10e | ||
All of | ||
Lenovo Thinkagile Hx Enclosure Certified Node Firmware | <tesm38c-1.26 | |
Lenovo Thinkagile Hx Enclosure Certified Node | ||
All of | ||
Lenovo Thinkagile Vx Enclosure Firmware | <tesm38c-1.26 | |
Lenovo Thinkagile Vx Enclosure | ||
All of | ||
Lenovo Thinksystem D2 Enclosure Firmware | <tesm38c-1.26 | |
Lenovo Thinksystem D2 Enclosure | ||
All of | ||
Lenovo Thinksystem Da240 Enclosure Firmware | <umsm10s-1.07 | |
Lenovo Thinksystem Da240 Enclosure | ||
All of | ||
Lenovo Thinksystem Dw612 Enclosure Firmware | <umsm10s-1.07 | |
Lenovo Thinksystem Dw612 Enclosure |
Upgrade to the firmware version (or newer) indicated for your model in the Lenovo Product Security: https://support.lenovo.com/us/en/product_security/LEN-127357
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2992 is an unauthenticated denial of service vulnerability in the SMM v1, SMM v2, and FPC management web server.
CVE-2023-2992 has a severity value of 7.5, indicating a high severity.
Lenovo Nextscale N1200 Enclosure Firmware, Lenovo Thinkagile Cp-cb-10 Firmware, Lenovo Thinkagile Cp-cb-10e Firmware, Lenovo Thinkagile Hx Enclosure Certified Node Firmware, Lenovo Thinkagile Vx Enclosure Firmware, Lenovo Thinksystem D2 Enclosure Firmware, Lenovo Thinksystem Da240 Enclosure Firmware, Lenovo Thinksystem Dw612 Enclosure Firmware
To fix CVE-2023-2992, reboot the SMM or FPC to restore access to the management web server.
More information about CVE-2023-2992 can be found at the following link: https://support.lenovo.com/us/en/product_security/LEN-127357