Medium severity5.4NVD Advisory· Published Jun 26, 2023· Updated Jun 17, 2026
CVE-2023-2993
CVE-2023-2993
Description
A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute.
Affected products
12- Range: various
- Range: various
- cpe:2.3:o:lenovo:nextscale_n1200_enclosure_firmware:*:*:*:*:*:*:*:*Range: <fhet60b-3.40
- cpe:2.3:o:lenovo:thinkagile_cp-cb-10_firmware:*:*:*:*:*:*:*:*Range: <tesm38c-1.26
- cpe:2.3:o:lenovo:thinkagile_cp-cb-10e_firmware:*:*:*:*:*:*:*:*Range: <tesm38c-1.26
- cpe:2.3:o:lenovo:thinkagile_hx_enclosure_certified_node_firmware:*:*:*:*:*:*:*:*Range: <tesm38c-1.26
- cpe:2.3:o:lenovo:thinkagile_vx_enclosure_firmware:*:*:*:*:*:*:*:*Range: <tesm38c-1.26
- cpe:2.3:o:lenovo:thinksystem_d2_enclosure_firmware:*:*:*:*:*:*:*:*Range: <tesm38c-1.26
- cpe:2.3:o:lenovo:thinksystem_da240_enclosure_firmware:*:*:*:*:*:*:*:*Range: <umsm10s-1.07
- cpe:2.3:o:lenovo:thinksystem_dw612_enclosure_firmware:*:*:*:*:*:*:*:*Range: <umsm10s-1.07
Patches
Vulnerability mechanics
References
1- support.lenovo.com/us/en/product_security/LEN-127357nvdVendor Advisory
News mentions
0No linked articles in our index yet.