6.3

CVE-2023-2993

A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute.

Data is provided by the National Vulnerability Database (NVD)
LenovoNextscale N1200 Enclosure Firmware Version < fhet60b-3.40
   LenovoNextscale N1200 Enclosure Version-
LenovoThinkagile Cp-cb-10 Firmware Version < tesm38c-1.26
   LenovoThinkagile Cp-cb-10 Version-
LenovoThinkagile Cp-cb-10e Firmware Version < tesm38c-1.26
   LenovoThinkagile Cp-cb-10e Version-
LenovoThinkagile Vx Enclosure Firmware Version < tesm38c-1.26
   LenovoThinkagile Vx Enclosure Version-
LenovoThinksystem D2 Enclosure Firmware Version < tesm38c-1.26
   LenovoThinksystem D2 Enclosure Version-
LenovoThinksystem Da240 Enclosure Firmware Version < umsm10s-1.07
LenovoThinksystem Dw612 Enclosure Firmware Version < umsm10s-1.07
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.245
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
psirt@lenovo.com 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CWE-281 Improper Preservation of Permissions

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.