Fiche vulnérabilité
CVE-2021-3849 : faille critique lenovo nextscale n1200 enclosure… (CVSS 9.8)
Description
An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not affected.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 22 avr. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- lenovo nextscale n1200 enclosure firmware
- lenovo thinkagile hx enclosure certified node firmware
- lenovo thinkagile vx enclosure firmware
- lenovo thinksystem d2 enclosure firmware
- ibm nextscale fan power controller firmware