First published: Mon Jun 26 2023(Updated: )
A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo NextScale N1200 Enclosure | <fhet60b-3.40 | |
Lenovo NextScale N1200 Enclosure | ||
Lenovo ThinkAgile CP-CB-10E | <tesm38c-1.26 | |
Lenovo ThinkAgile CP-CB-10 | ||
Lenovo ThinkAgile CP-CB-10E | <tesm38c-1.26 | |
Lenovo ThinkAgile CP-CB-10E Firmware | ||
lenovo thinkagile hx enclosure certified node firmware | <tesm38c-1.26 | |
lenovo thinkagile hx enclosure certified node | ||
Lenovo ThinkAgile VX Enclosure | <tesm38c-1.26 | |
Lenovo ThinkAgile VX Enclosure 7Y91 | ||
Lenovo ThinkSystem D2 Enclosure | <tesm38c-1.26 | |
Lenovo ThinkSystem D2 Enclosure | ||
Lenovo ThinkSystem DA240 Enclosure Firmware | <umsm10s-1.07 | |
Lenovo ThinkSystem DA240 Enclosure Firmware | ||
Lenovo ThinkSystem DW612 Enclosure Firmware | <umsm10s-1.07 | |
lenovo thinksystem dw612 enclosure |
Upgrade to the firmware version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-127357 https://support.lenovo.com/us/en/product_security/LEN-127357
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-2993.
The severity of CVE-2023-2993 is medium with a severity value of 6.3.
A valid authenticated user with limited privileges can exploit CVE-2023-2993 by using specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC.
The Lenovo Nextscale N1200 Enclosure Firmware up to and excluding version fhet60b-3.40, Lenovo Thinkagile Cp-cb-10 Firmware up to and excluding version tesm38c-1.26, Lenovo Thinkagile Cp-cb-10e Firmware up to and excluding version tesm38c-1.26, Lenovo Thinkagile Hx Enclosure Certified Node Firmware up to and excluding version tesm38c-1.26, Lenovo Thinkagile Vx Enclosure Firmware up to and excluding version tesm38c-1.26, Lenovo Thinksystem D2 Enclosure Firmware up to and excluding version tesm38c-1.26, Lenovo Thinksystem Da240 Enclosure Firmware up to and excluding version umsm10s-1.07, and Lenovo Thinksystem Dw612 Enclosure Firmware up to and excluding version umsm10s-1.07 are affected by CVE-2023-2993.
You can find more information about CVE-2023-2993 on the Lenovo Product Security website: [https://support.lenovo.com/us/en/product_security/LEN-127357](https://support.lenovo.com/us/en/product_security/LEN-127357)