CVE-2024-2659
—CVSS 3.1
7.2 high
EPSS
1%p64
Published
()
Modified
Description
A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function.
- Vendors
- lenovo
- Products
- nextscale n1200 enclosure firmware, thinkagile cp-cb-10 firmware, thinkagile cp-cb-10e firmware, thinkagile hx enclosure firmware, thinkagile hx3721 firmware, thinkagile hx1021 firmware, thinkagile hx e1 enclosure firmware, thinkagile hx e2 enclosure firmware, thinkagile hx1321 firmware, thinkagile hx2321 firmware, thinkagile hx3321 firmware, thinkagile hx1331 firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.