Lenovo

System Management Module Firmware

13 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.43%
  • Published 15.04.2024 18:15:10
  • Last modified 28.07.2025 13:06:05

A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function.

  • EPSS 0.37%
  • Published 15.04.2024 18:15:09
  • Last modified 21.11.2024 08:36:07

A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute unauthorized commands via IPMI.

  • EPSS 0.39%
  • Published 15.04.2024 18:15:09
  • Last modified 21.11.2024 08:36:07

A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a specific API endpoint.

  • EPSS 0.09%
  • Published 15.04.2024 18:15:09
  • Last modified 21.11.2024 08:36:07

An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI calls that could lead to exposure of limited system information.

  • EPSS 1.07%
  • Published 27.11.2018 14:29:00
  • Last modified 21.11.2024 03:52:05

In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user.

  • EPSS 0.97%
  • Published 27.11.2018 14:29:00
  • Last modified 21.11.2024 03:52:05

In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to post-authentication command injection.

  • EPSS 0.38%
  • Published 27.11.2018 14:29:00
  • Last modified 21.11.2024 03:52:05

In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to several buffer overflows.

  • EPSS 0.33%
  • Published 27.11.2018 14:29:00
  • Last modified 21.11.2024 03:52:05

In System Management Module (SMM) versions prior to 1.06, the FFDC feature includes the collection of SMM system files containing sensitive information; notably, the SMM user account credentials and the system shadow file.

  • EPSS 0.54%
  • Published 27.11.2018 14:29:00
  • Last modified 21.11.2024 03:52:05

In System Management Module (SMM) versions prior to 1.06, an internal SMM function that retrieves configuration settings is prone to a buffer overflow.

  • EPSS 0.31%
  • Published 27.11.2018 14:29:00
  • Last modified 21.11.2024 03:52:05

In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a debug log when user authentication fails.