First published: Mon Jun 26 2023(Updated: )
A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Nextscale N1200 Enclosure Firmware | <fhet60b-3.40 | |
Lenovo Nextscale N1200 Enclosure | ||
Lenovo Thinkagile Cp-cb-10 Firmware | <tesm38c-1.26 | |
Lenovo Thinkagile Cp-cb-10 | ||
Lenovo Thinkagile Cp-cb-10e Firmware | <tesm38c-1.26 | |
Lenovo Thinkagile Cp-cb-10e | ||
Lenovo Thinkagile Hx Enclosure Certified Node Firmware | <tesm38c-1.26 | |
Lenovo Thinkagile Hx Enclosure Certified Node | ||
Lenovo Thinkagile Vx Enclosure Firmware | <tesm38c-1.26 | |
Lenovo Thinkagile Vx Enclosure | ||
Lenovo Thinksystem D2 Enclosure Firmware | <tesm38c-1.26 | |
Lenovo Thinksystem D2 Enclosure | ||
Lenovo Thinksystem Da240 Enclosure Firmware | <umsm10s-1.07 | |
Lenovo Thinksystem Da240 Enclosure | ||
Lenovo Thinksystem Dw612 Enclosure Firmware | <umsm10s-1.07 | |
Lenovo Thinksystem Dw612 Enclosure |
Upgrade to the firmware version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-127357 https://support.lenovo.com/us/en/product_security/LEN-127357
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-2993.
The severity of CVE-2023-2993 is medium with a severity value of 6.3.
A valid authenticated user with limited privileges can exploit CVE-2023-2993 by using specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC.
The Lenovo Nextscale N1200 Enclosure Firmware up to and excluding version fhet60b-3.40, Lenovo Thinkagile Cp-cb-10 Firmware up to and excluding version tesm38c-1.26, Lenovo Thinkagile Cp-cb-10e Firmware up to and excluding version tesm38c-1.26, Lenovo Thinkagile Hx Enclosure Certified Node Firmware up to and excluding version tesm38c-1.26, Lenovo Thinkagile Vx Enclosure Firmware up to and excluding version tesm38c-1.26, Lenovo Thinksystem D2 Enclosure Firmware up to and excluding version tesm38c-1.26, Lenovo Thinksystem Da240 Enclosure Firmware up to and excluding version umsm10s-1.07, and Lenovo Thinksystem Dw612 Enclosure Firmware up to and excluding version umsm10s-1.07 are affected by CVE-2023-2993.
You can find more information about CVE-2023-2993 on the Lenovo Product Security website: [https://support.lenovo.com/us/en/product_security/LEN-127357](https://support.lenovo.com/us/en/product_security/LEN-127357)