cbcvebase.
CVE-2023-2993
published 2023-06-26

CVE-2023-2993: A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of…

PriorityP336medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.29%
20.8th percentile
A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute.

Affected

10 ranges
VendorProductVersion rangeFixed in
lenovofan_power_controller
lenovonextscale_n1200_enclosure_firmware< fhet60b-3.40fhet60b-3.40
lenovosystem_management_module
lenovothinkagile_cp-cb-10_firmware< tesm38c-1.26tesm38c-1.26
lenovothinkagile_cp-cb-10e_firmware< tesm38c-1.26tesm38c-1.26
lenovothinkagile_hx_enclosure_certified_node_firmware< tesm38c-1.26tesm38c-1.26
lenovothinkagile_vx_enclosure_firmware< tesm38c-1.26tesm38c-1.26
lenovothinksystem_d2_enclosure_firmware< tesm38c-1.26tesm38c-1.26
lenovothinksystem_da240_enclosure_firmware< umsm10s-1.07umsm10s-1.07
lenovothinksystem_dw612_enclosure_firmware< umsm10s-1.07umsm10s-1.07
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.