A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute unauthorized commands via IPMI.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update SMM/SMM2 or FPC to the version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-140420
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54695 | A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute unauthorized commands via IPMI. |
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-140420 |
|
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-02T07:38:00.762Z
Reserved: 2023-09-08T19:23:04.502Z
Link: CVE-2023-4855
Updated: 2024-08-02T07:38:00.762Z
Status : Deferred
Published: 2024-04-15T18:15:09.260
Modified: 2026-06-17T06:38:45.583
Link: CVE-2023-4855
No data.
OpenCVE Enrichment
No data.
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
EUVD