CVE-2023-4857

An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI calls that could lead to exposure of limited system information.
Configurations

No configuration.

History

21 Nov 2024, 08:36

Type Values Removed Values Added
References () https://support.lenovo.com/us/en/product_security/LEN-140420 - () https://support.lenovo.com/us/en/product_security/LEN-140420 -
Summary
  • (es) Se identificó una vulnerabilidad de omisión de autenticación en SMM/SMM2 y FPC que podría permitir a un usuario autenticado ejecutar ciertas llamadas IPMI que podrían provocar la exposición de información limitada del sistema.

15 Apr 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-15 18:15

Updated : 2024-11-21 08:36


NVD link : CVE-2023-4857

Mitre link : CVE-2023-4857

CVE.ORG link : CVE-2023-4857


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function