7.5

CVE-2023-2992

An unauthenticated  denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions.  Rebooting SMM or FPC will restore access to the management web server.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo ≫ Nextscale N1200 Enclosure Firmware Version < fhet60b-3.40
   Lenovo ≫ Nextscale N1200 Enclosure Version -
Lenovo ≫ Thinkagile Cp-cb-10 Firmware Version < tesm38c-1.26
   Lenovo ≫ Thinkagile Cp-cb-10 Version -
Lenovo ≫ Thinkagile Cp-cb-10e Firmware Version < tesm38c-1.26
   Lenovo ≫ Thinkagile Cp-cb-10e Version -
Lenovo ≫ Thinkagile Vx Enclosure Firmware Version < tesm38c-1.26
   Lenovo ≫ Thinkagile Vx Enclosure Version -
Lenovo ≫ Thinksystem D2 Enclosure Firmware Version < tesm38c-1.26
   Lenovo ≫ Thinksystem D2 Enclosure Version -
Lenovo ≫ Thinksystem Da240 Enclosure Firmware Version < umsm10s-1.07
   Lenovo ≫ Thinksystem Da240 Enclosure Version -
Lenovo ≫ Thinksystem Dw612 Enclosure Firmware Version < umsm10s-1.07
   Lenovo ≫ Thinksystem Dw612 Enclosure Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.62% 0.45
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Lenovo 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-405 Asymmetric Resource Consumption (Amplification)

The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric."

https://support.lenovo.com/us/en/product_security/LEN-127357
Vendor Advisory