Vulnerability Description
A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Nextscale N1200 Enclosure Firmware | < FHET62A-3.50 |
| Lenovo | Nextscale N1200 Enclosure | - |
| Lenovo | Thinkagile Cp-Cb-10 Firmware | < TESM40B-1.27 |
| Lenovo | Thinkagile Cp-Cb-10 | - |
| Lenovo | Thinkagile Cp-Cb-10E Firmware | < TESM40B-1.27 |
| Lenovo | Thinkagile Cp-Cb-10E | - |
| Lenovo | Thinkagile Hx Enclosure Firmware | < tesm40b-1.27 |
| Lenovo | Thinkagile Hx Enclosure | - |
| Lenovo | Thinkagile Hx3721 Firmware | < tesm40b-1.27 |
| Lenovo | Thinkagile Hx3721 | - |
| Lenovo | Thinkagile Hx1021 Firmware | < tesm40b-1.27 |
| Lenovo | Thinkagile Hx1021 | - |
| Lenovo | Thinkagile Hx E1 Enclosure Firmware | < tesm40b-1.27 |
| Lenovo | Thinkagile Hx E1 Enclosure | - |
| Lenovo | Thinkagile Hx E2 Enclosure Firmware | < tesm40b-1.27 |
| Lenovo | Thinkagile Hx E2 Enclosure | - |
| Lenovo | Thinkagile Hx1321 Firmware | < tesm40b-1.27 |
| Lenovo | Thinkagile Hx1321 | - |
| Lenovo | Thinkagile Hx2321 Firmware | < tesm40b-1.27 |
| Lenovo | Thinkagile Hx2321 | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/LEN-140420Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-140420Vendor Advisory
FAQ
What is CVE-2024-2659?
CVE-2024-2659 is a vulnerability with a CVSS score of 7.2 (HIGH). A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrati...
How severe is CVE-2024-2659?
CVE-2024-2659 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-2659?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Nextscale N1200 Enclosure Firmware, Lenovo Nextscale N1200 Enclosure, Lenovo Thinkagile Cp-Cb-10 Firmware, Lenovo Thinkagile Cp-Cb-10, Lenovo Thinkagile Cp-Cb-10E Firmware.