GPU VulnDB

Database/Control plane, storage & DevOps

Lenovo ThinkSystem SMM / SMM2 and FPC (command injection): An authenticated user with elevated privileges executes

CVE-2024-2659Control plane, storage & DevOpscurated

Impact

An authenticated user with elevated privileges executes system commands on the chassis System Management Module or Fan/Power Controller - the components that own power and thermal control for a whole enclosure of ThinkSystem nodes.

Who can reach it

Authenticated high-privilege access to the SMM/SMM2 or FPC management interface.

What to do

Apply the Lenovo firmware update per LEN-140420. Chassis-level management firmware flash; nodes keep running but chassis management is interrupted during the update.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.