PT-2022-10823 · Lenovo · Lenovo System Management Module+1

Published

2022-04-22

·

Updated

2022-08-09

·

CVE-2021-3897

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware (affected versions not specified) SMM2 is not affected.
Description An authentication bypass issue was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware. This could allow an unauthenticated attacker to execute commands on the SMM and FPC2.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2021-3897

Affected Products

Lenovo Fan Power Controller2
Lenovo System Management Module