CVE-2024-45656

CRITICALCVSS 9.8/10EPSS 0.43%

Last modified

CVE-2024-45656 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, and FW1060.00 through FW1060.10 has static credentials which may allow network users to gain service privileges to the FSP.. EPSS estimates a 0.43% chance of exploitation in the next 30 days.

Description

IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, and FW1060.00 through FW1060.10 has static credentials which may allow network users to gain service privileges to the FSP.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.43%

34.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IbmPower System E1080 \(9080-Hex\) Firmware>= FW1030.00, <= FW1030.61
IbmPower System E1080 \(9080-Hex\) Firmware>= FW1050.00, <= FW1050.21
IbmPower System E1080 \(9080-Hex\) Firmware>= FW1060.00, <= FW1060.10
IbmPower System L922 \(9008-22l\) Firmware>= FW950.00, <= FW950.C0
IbmPower System S922 \(9009-22a\) Firmware>= FW950.00, <= FW950.C0
IbmPower System S922 \(9009-22g\) Firmware>= FW950.00, <= FW950.C0
IbmPower System H922 \(9223-22h\) Firmware>= FW950.00, <= FW950.C0
IbmPower System H922 \(9223-22s\) Firmware>= FW950.00, <= FW950.C0
IbmPower System S914 \(9009-41a\) Firmware>= FW950.00, <= FW950.C0
IbmPower System S914 \(9009-41g\) Firmware>= FW950.00, <= FW950.C0
IbmPower System S924 \(9009-42a\) Firmware>= FW950.00, <= FW950.C0
IbmPower System S924 \(9009-42g\) Firmware>= FW950.00, <= FW950.C0
IbmPower System H924 \(9223-42h\) Firmware>= FW950.00, <= FW950.C0
IbmPower System H924 \(9223-42s\) Firmware>= FW950.00, <= FW950.C0
IbmPower System E950 \(9040-Mr9\) Firmware>= FW950.00, <= FW950.C0
IbmPower System E980 \(9080-M9s\) Firmware>= FW950.00, <= FW950.C0
IbmEss 5000 \(5105-22e\) Firmware>= FW950.00, <= FW950.C0
IbmPower System S812 \(8284-21a\) Firmware>= FW860.00, <= FW860.B3
IbmPower System S822 \(8284-22a\) Firmware>= FW860.00, <= FW860.B3
IbmPower System S814 \(8286-41a\) Firmware>= FW860.00, <= FW860.B3
IbmPower System S824 \(8286-42a\) Firmware>= FW860.00, <= FW860.B3
IbmPower System S812l \(8247-21l\) Firmware>= FW860.00, <= FW860.B3
IbmPower System S822l \(8247-22l\) Firmware>= FW860.00, <= FW860.B3
IbmPower System S824l \(8247-42l\) Firmware>= FW860.00, <= FW860.B3
IbmPower System E850 \(8408-E8e\) Firmware>= FW860.00, <= FW860.B3
IbmPower System E850c \(8408-44e\) Firmware>= FW860.00, <= FW860.B3
IbmPower System E870 \(9119-Mme\) Firmware>= FW860.00, <= FW860.B3
IbmPower System E880 \(9119-Mhe\) Firmware>= FW860.00, <= FW860.B3
IbmPower System E870c \(9080-Mme\) Firmware>= FW860.00, <= FW860.B3
IbmPower System E880c \(9080-Mhe\) Firmware>= FW860.00, <= FW860.B3

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2024-45656?
IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, and FW1060.00 through FW1060.10 has static credentials which may allow network users to gain service privileges to the FSP.
How severe is CVE-2024-45656?
CVE-2024-45656 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 0.43% probability of exploitation in the next 30 days.
How do I fix CVE-2024-45656?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2024-45656?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST