An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI calls that could lead to exposure of limited system information.

Project Subscriptions

No data.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-54697 An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI calls that could lead to exposure of limited system information.
Fixes

Solution

Update SMM/SMM2 or FPC to the version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-140420    


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-02T07:38:00.772Z

Reserved: 2023-09-08T19:23:06.855Z

Link: CVE-2023-4857

cve-icon Vulnrichment

Updated: 2024-08-02T07:38:00.772Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-15T18:15:09.640

Modified: 2024-11-21T08:36:07.400

Link: CVE-2023-4857

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses