CVE-2024-2659
EUVD-2024-2760715.04.2024, 18:15
A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| lenovo | fan_power_controller | 𝑥 < fhet62a-3.50 | ADP |
| lenovo | system_management_module_firmware | 1.24 ≤ 𝑥 < tesm40b-1.27 | ADP |