CVE-2023-4855
EUVD-2023-5469515.04.2024, 18:15
A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute unauthorized commands via IPMI.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| lenovo | fan_power_controller | 𝑥 < fhet62a-3.50 | ADP |
| lenovo | system_management_module_firmware | 1.24 ≤ 𝑥 < tesm40b-1.27 | ADP |