CVE-2023-4856
EUVD-2023-5469615.04.2024, 18:15
A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a specific API endpoint.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| lenovo | fan_power_controller | 𝑥 < fhet62a-3.50 | ADP |
| lenovo | system_management_module_firmware | 1.24 ≤ 𝑥 < tesm40b-1.27 | ADP |