PT-2022-10733 · Lenovo · Lenovo System Management Module+1

Published

2022-04-22

·

Updated

2022-10-27

·

CVE-2021-3849

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lenovo Fan Power Controller2 (FPC2) (affected versions not specified) Lenovo System Management Module (SMM) (affected versions not specified)
Description An authentication bypass issue was found in the web interface of the Lenovo Fan Power Controller2 and Lenovo System Management Module firmware, allowing an unauthenticated attacker to execute commands on the affected systems.
Recommendations For Lenovo Fan Power Controller2, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Lenovo System Management Module, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2021-3849

Affected Products

Lenovo Fan Power Controller2
Lenovo System Management Module