SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-2992

An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions.

HIGH 7.5EPSS 0.62%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.62%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An unauthenticated  denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions. Rebooting SMM or FPC will restore access to the management web server.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
0.62% probability · 48th percentile
CISA KEV
Not listed
Weakness
CWE-405
Affected
lenovo/nextscale n1200 enclosure firmware · lenovo/thinkagile cp-cb-10 firmware · lenovo/thinkagile cp-cb-10e firmware · lenovo/thinkagile hx enclosure certified node firmware · lenovo/thinkagile vx enclosure firmware · lenovo/thinksystem d2 enclosure firmware · lenovo/thinksystem da240 enclosure firmware · lenovo/thinksystem dw612 enclosure firmware
Source
psirt@lenovo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.