Vulnerability Description
IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, and FW1060.00 through FW1060.10 has static credentials which may allow network users to gain service privileges to the FSP.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Power System E1080 \(9080-Hex\) Firmware | >= FW1030.00, <= FW1030.61 |
| Ibm | Power System E1080 \(9080-Hex\) | - |
| Ibm | Power System L922 \(9008-22L\) Firmware | >= FW950.00, <= FW950.C0 |
| Ibm | Power System L922 \(9008-22L\) | - |
| Ibm | Power System S922 \(9009-22A\) Firmware | >= FW950.00, <= FW950.C0 |
| Ibm | Power System S922 \(9009-22A\) | - |
| Ibm | Power System S922 \(9009-22G\) Firmware | >= FW950.00, <= FW950.C0 |
| Ibm | Power System S922 \(9009-22G\) | - |
| Ibm | Power System H922 \(9223-22H\) Firmware | >= FW950.00, <= FW950.C0 |
| Ibm | Power System H922 \(9223-22H\) | - |
| Ibm | Power System H922 \(9223-22S\) Firmware | >= FW950.00, <= FW950.C0 |
| Ibm | Power System H922 \(9223-22S\) | - |
| Ibm | Power System S914 \(9009-41A\) Firmware | >= FW950.00, <= FW950.C0 |
| Ibm | Power System S914 \(9009-41A\) | - |
| Ibm | Power System S914 \(9009-41G\) Firmware | >= FW950.00, <= FW950.C0 |
| Ibm | Power System S914 \(9009-41G\) | - |
| Ibm | Power System S924 \(9009-42A\) Firmware | >= FW950.00, <= FW950.C0 |
| Ibm | Power System S924 \(9009-42A\) | - |
| Ibm | Power System S924 \(9009-42G\) Firmware | >= FW950.00, <= FW950.C0 |
| Ibm | Power System S924 \(9009-42G\) | - |
Related Weaknesses (CWE)
References
- https://www.ibm.com/support/pages/node/7174183Vendor Advisory
FAQ
What is CVE-2024-45656?
CVE-2024-45656 is a vulnerability with a CVSS score of 9.8 (CRITICAL). IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, and FW1060.00 through FW1060.10 has static credenti...
How severe is CVE-2024-45656?
CVE-2024-45656 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-45656?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Power System E1080 \(9080-Hex\) Firmware, Ibm Power System E1080 \(9080-Hex\), Ibm Power System L922 \(9008-22L\) Firmware, Ibm Power System L922 \(9008-22L\), Ibm Power System S922 \(9009-22A\) Firmware.