CVE-2021-3849

CRITICAL

Lenovo Fan Power Controller2/FPC2 - Auth Bypass

Title source: llm
STIX 2.1

Description

An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not affected.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0070
EPSS Percentile 72.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-288
Status published
Products (5)
ibm/nextscale_fan_power_controller_firmware < 44a-3.70
lenovo/nextscale_n1200_enclosure_firmware < fhet50b-2.90
lenovo/thinkagile_hx_enclosure_certified_node_firmware < tesm28b-1.21
lenovo/thinkagile_vx_enclosure_firmware < tesm28b-1.21
lenovo/thinksystem_d2_enclosure_firmware < tesm28b-1.21
Published Apr 22, 2022
Tracked Since Feb 18, 2026