CVE-2024-2659

high-risk
Published 2024-04-15

A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function.

Do I need to act?

-
0.43% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.2/10 High
NETWORK / LOW complexity

Affected Products (20)

Nextscale N1200 Enclosure Firmware
Thinkagile Cp-Cb-10 Firmware
Thinkagile Cp-Cb-10E Firmware
Thinkagile Hx Enclosure Firmware
Thinkagile Hx3721 Firmware
Thinkagile Hx1021 Firmware
Thinkagile Hx E1 Enclosure Firmware
Thinkagile Hx E2 Enclosure Firmware
Thinkagile Hx1321 Firmware
Thinkagile Hx2321 Firmware
Thinkagile Hx3321 Firmware
Thinkagile Hx1331 Firmware
Thinkagile Hx2331 Firmware
Thinkagile Hx3331 Firmware
Thinkagile Hx630 V3 Firmware
Thinkagile Hx3376 Firmware
Thinkagile Hx645 V3 Firmware
Thinkagile Hx1521-R Firmware
Thinkagile Hx3521-G Firmware
Thinkagile Hx5521 Firmware

Affected Vendors

56
/ 100
high-risk
Severity 26/34 · High
Exploitability 2/34 · Minimal
Exposure 28/34 · Critical