CVE-2023-2993
published 2023-06-26CVE-2023-2993: A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of…
PriorityP336medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.29%
20.8th percentile
A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lenovo | fan_power_controller | — | — |
| lenovo | nextscale_n1200_enclosure_firmware | < fhet60b-3.40 | fhet60b-3.40 |
| lenovo | system_management_module | — | — |
| lenovo | thinkagile_cp-cb-10_firmware | < tesm38c-1.26 | tesm38c-1.26 |
| lenovo | thinkagile_cp-cb-10e_firmware | < tesm38c-1.26 | tesm38c-1.26 |
| lenovo | thinkagile_hx_enclosure_certified_node_firmware | < tesm38c-1.26 | tesm38c-1.26 |
| lenovo | thinkagile_vx_enclosure_firmware | < tesm38c-1.26 | tesm38c-1.26 |
| lenovo | thinksystem_d2_enclosure_firmware | < tesm38c-1.26 | tesm38c-1.26 |
| lenovo | thinksystem_da240_enclosure_firmware | < umsm10s-1.07 | umsm10s-1.07 |
| lenovo | thinksystem_dw612_enclosure_firmware | < umsm10s-1.07 | umsm10s-1.07 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-06-26
Published