ZeroHour

CVE-2023-2993

CVSS 3.1
6.3 medium
EPSS
<1%p21
Published
()
Modified
Description

A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute.

Vendors
lenovo
Products
nextscale n1200 enclosure firmware, thinkagile cp-cb-10 firmware, thinkagile cp-cb-10e firmware, thinkagile hx enclosure certified node firmware, thinkagile vx enclosure firmware, thinksystem d2 enclosure firmware, thinksystem da240 enclosure firmware, thinksystem dw612 enclosure firmware
Weakness
CWE-281
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.