Lenovo ThinkSystem是中国联想(Lenovo)公司的一款ThinkSystem系列服务器设备。 Lenovo ThinkSystem存在安全漏洞。攻击者利用该漏洞使用专门设计的 Web 管理服务器 API 调用在 SMM v1、SMM v2 和 FPC 上执行没有足够权限的命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Lenovo | System Management Module (SMM) | various | - |
|
| Lenovo | Fan Power Controller (FPC) | various | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-3113 | 8.2 HIGH | Lenovo XClarity Administrator 代码问题漏洞 |
| CVE-2023-34418 | 8.1 HIGH | Lenovo XClarity Administrator SQL注入漏洞 |
| CVE-2023-2992 | 7.5 HIGH | Lenovo ThinkSystem 安全漏洞 |
| CVE-2023-34420 | 7.2 HIGH | Lenovo XClarity Administrator 操作系统命令注入漏洞 |
| CVE-2023-34421 | 6.5 MEDIUM | Lenovo XClarity Administrator 输入验证错误漏洞 |
| CVE-2023-34422 | 6.5 MEDIUM | Lenovo XClarity Administrator 输入验证错误漏洞 |
| CVE-2023-2290 | 6.4 MEDIUM | Lenovo ThinkPad 安全漏洞 |
No comments yet