CVE-2024-2659
- EPSS 0.43%
- Veröffentlicht 15.04.2024 18:15:10
- Zuletzt bearbeitet 28.07.2025 13:06:05
A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function.
CVE-2023-4855
- EPSS 0.37%
- Veröffentlicht 15.04.2024 18:15:09
- Zuletzt bearbeitet 21.11.2024 08:36:07
A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute unauthorized commands via IPMI.
CVE-2023-4856
- EPSS 0.39%
- Veröffentlicht 15.04.2024 18:15:09
- Zuletzt bearbeitet 21.11.2024 08:36:07
A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a specific API endpoint.
CVE-2023-4857
- EPSS 0.09%
- Veröffentlicht 15.04.2024 18:15:09
- Zuletzt bearbeitet 21.11.2024 08:36:07
An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI calls that could lead to exposure of limited system information.
CVE-2018-16089
- EPSS 1.07%
- Veröffentlicht 27.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:05
In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user.
CVE-2018-16090
- EPSS 0.97%
- Veröffentlicht 27.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:05
In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to post-authentication command injection.
CVE-2018-16091
- EPSS 0.38%
- Veröffentlicht 27.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:05
In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to several buffer overflows.
CVE-2018-16092
- EPSS 0.33%
- Veröffentlicht 27.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:05
In System Management Module (SMM) versions prior to 1.06, the FFDC feature includes the collection of SMM system files containing sensitive information; notably, the SMM user account credentials and the system shadow file.
CVE-2018-16094
- EPSS 0.54%
- Veröffentlicht 27.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:05
In System Management Module (SMM) versions prior to 1.06, an internal SMM function that retrieves configuration settings is prone to a buffer overflow.
CVE-2018-16095
- EPSS 0.31%
- Veröffentlicht 27.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:05
In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a debug log when user authentication fails.