V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2023-2992
CVE
High

An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under…

CVSS
7.5
High
EPSS
0.00
p52
Published
2023-01-01
Updated
2023-01-01
Description

An unauthenticated  denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions. Rebooting SMM or FPC will restore access to the management web server.

Tags · CWE
Pre-auth
CWE-405
Affected products
Nextscale_n1200_enclosure_firmwareThinkagile_cp-cb-10_firmwareThinkagile_cp-cb-10e_firmwareThinkagile_hx_enclosure_certified_node_firmwareThinkagile_vx_enclosure_firmwareThinksystem_d2_enclosure_firmwareThinksystem_da240_enclosure_firmwareThinksystem_dw612_enclosure_firmware
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.003 · p52
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
nextscale_n1200_enclosure_firmware*Tracked
thinkagile_cp-cb-10_firmware*Tracked
thinkagile_cp-cb-10e_firmware*Tracked
thinkagile_hx_enclosure_certified_node_firmware*Tracked
thinkagile_vx_enclosure_firmware*Tracked
thinksystem_d2_enclosure_firmware*Tracked
thinksystem_da240_enclosure_firmware*Tracked
thinksystem_dw612_enclosure_firmware*Tracked
Source databases
CVE