CVE-2024-2659
HIGHDescription
A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function.
Is your site exposed to CVE-2024-2659?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| lenovo | nextscale_n1200_enclosure_firmware |
| lenovo | nextscale_n1200_enclosure |
| lenovo | thinkagile_cp-cb-10_firmware |
| lenovo | thinkagile_cp-cb-10 |
| lenovo | thinkagile_cp-cb-10e_firmware |
| lenovo | thinkagile_cp-cb-10e |
| lenovo | thinkagile_hx_enclosure_firmware |
| lenovo | thinkagile_hx_enclosure |
| lenovo | thinkagile_hx3721_firmware |
| lenovo | thinkagile_hx3721 |
| lenovo | thinkagile_hx1021_firmware |
| lenovo | thinkagile_hx1021 |
| lenovo | thinkagile_hx_e1_enclosure_firmware |
| lenovo | thinkagile_hx_e1_enclosure |
| lenovo | thinkagile_hx_e2_enclosure_firmware |
| lenovo | thinkagile_hx_e2_enclosure |
| lenovo | thinkagile_hx1321_firmware |
| lenovo | thinkagile_hx1321 |
| lenovo | thinkagile_hx2321_firmware |
| lenovo | thinkagile_hx2321 |
| lenovo | thinkagile_hx3321_firmware |
| lenovo | thinkagile_hx3321 |
| lenovo | thinkagile_hx1331_firmware |
| lenovo | thinkagile_hx1331 |
| lenovo | thinkagile_hx2331_firmware |
| lenovo | thinkagile_hx2331 |
| lenovo | thinkagile_hx3331_firmware |
| lenovo | thinkagile_hx3331 |
| lenovo | thinkagile_hx630_v3_firmware |
| lenovo | thinkagile_hx630_v3 |
| lenovo | thinkagile_hx3376_firmware |
| lenovo | thinkagile_hx3376 |
| lenovo | thinkagile_hx645_v3_firmware |
| lenovo | thinkagile_hx645_v3 |
| lenovo | thinkagile_hx1521-r_firmware |
| lenovo | thinkagile_hx1521-r |
| lenovo | thinkagile_hx3521-g_firmware |
| lenovo | thinkagile_hx3521-g |
| lenovo | thinkagile_hx5521_firmware |
| lenovo | thinkagile_hx5521 |
| lenovo | thinkagile_hx5521-c_firmware |
| lenovo | thinkagile_hx5521-c |
| lenovo | thinkagile_hx7521_firmware |
| lenovo | thinkagile_hx7521 |
| lenovo | thinkagile_hx5531_firmware |
| lenovo | thinkagile_hx5531 |
| lenovo | thinkagile_hx7531_firmware |
| lenovo | thinkagile_hx7531 |
| lenovo | thinkagile_hx650_v3_firmware |
| lenovo | thinkagile_hx650_v3 |
| lenovo | thinkagile_hx665_v3_firmware |
| lenovo | thinkagile_hx665_v3 |
| lenovo | thinkagile_hx7821_firmware |
| lenovo | thinkagile_hx7821 |
| lenovo | thinkagile_vx3720_firmware |
| lenovo | thinkagile_vx3720 |
| lenovo | thinkagile_2u4n_firmware |
| lenovo | thinkagile_2u4n |
| lenovo | thinkagile_vx1320_firmware |
| lenovo | thinkagile_vx1320 |
| lenovo | thinkagile_vx_1se_firmware |
| lenovo | thinkagile_vx_1se |
| lenovo | thinkagile_vx3320_firmware |
| lenovo | thinkagile_vx3320 |
| lenovo | thinkagile_vx2320_firmware |
| lenovo | thinkagile_vx2320 |
| lenovo | thinkagile_vx7320-n_firmware |
| lenovo | thinkagile_vx7320-n |
| lenovo | thinkagile_vx_1u_firmware |
| lenovo | thinkagile_vx_1u |
| lenovo | thinkagile_vx2330_firmware |
| lenovo | thinkagile_vx2330 |
| lenovo | thinkagile_vx3330_firmware |
| lenovo | thinkagile_vx3330 |
| lenovo | thinkagile_vx7330-n_firmware |
| lenovo | thinkagile_vx7330-n |
| lenovo | thinkagile_vx3331_firmware |
| lenovo | thinkagile_vx3331 |
| lenovo | thinkagile_vx630_v3_firmware |
| lenovo | thinkagile_vx630_v3 |
| lenovo | thinkagile_vx630_v4_firmware |
| lenovo | thinkagile_vx630_v4 |
| lenovo | thinkagile_vx635_v3_firmware |
| lenovo | thinkagile_vx635_v3 |
| lenovo | thinkagile_vx2375_firmware |
| lenovo | thinkagile_vx2375 |
| lenovo | thinkagile_vx3375_firmware |
| lenovo | thinkagile_vx3375 |
| lenovo | thinkagile_vx7375-n_firmware |
| lenovo | thinkagile_vx7375-n |
| lenovo | thinkagile_vx3376_firmware |
| lenovo | thinkagile_vx3376 |
| lenovo | thinkagile_vx645_v3_firmware |
| lenovo | thinkagile_vx645_v3 |
| lenovo | thinkagile_vx5520_firmware |
| lenovo | thinkagile_vx5520 |
| lenovo | thinkagile_vx7520_firmware |
| lenovo | thinkagile_vx7520 |
| lenovo | thinkagile_vx3520-g_firmware |
| lenovo | thinkagile_vx3520-g |
| lenovo | thinkagile_vx5520_firmware |
| lenovo | thinkagile_vx5520 |
| lenovo | thinkagile_vx_2u_firmware |
| lenovo | thinkagile_vx_2u |
| lenovo | thinkagile_vx3530-g_firmware |
| lenovo | thinkagile_vx3530-g |
| lenovo | thinkagile_vx5530_firmware |
| lenovo | thinkagile_vx5530 |
| lenovo | thinkagile_vx7530_firmware |
| lenovo | thinkagile_vx7530 |
| lenovo | thinkagile_vx7531_firmware |
| lenovo | thinkagile_vx7531 |
| lenovo | thinkagile_vx650_v3_firmware |
| lenovo | thinkagile_vx650_v3 |
| lenovo | thinkagile_vx650_v4_firmware |
| lenovo | thinkagile_vx650_v4 |
| lenovo | thinkagile_vx655_v3_firmware |
| lenovo | thinkagile_vx655_v3 |
| lenovo | thinkagile_vx5575_firmware |
| lenovo | thinkagile_vx5575 |
| lenovo | thinkagile_vx7575_firmware |
| lenovo | thinkagile_vx7575 |
| lenovo | thinkagile_vx3575-g_firmware |
| lenovo | thinkagile_vx3575-g |
| lenovo | thinkagile_vx665_v3_firmware |
| lenovo | thinkagile_vx665_v3 |
| lenovo | thinkagile_vx850_v3_firmware |
| lenovo | thinkagile_vx850_v3 |
| lenovo | thinkagile_vx_4u_firmware |
| lenovo | thinkagile_vx_4u |
| lenovo | thinkagile_vx7820_firmware |
| lenovo | thinkagile_vx7820 |
| lenovo | thinksystem_d2_enclosure_firmware |
| lenovo | thinksystem_d2_enclosure |
| lenovo | thinksystem_da240_firmware |
| lenovo | thinksystem_da240 |
| lenovo | thinksystem_dw612_firmware |
| lenovo | thinksystem_dw612 |
References
Frequently Asked Questions
What is CVE-2024-2659? +
How severe is CVE-2024-2659? +
What products are affected by CVE-2024-2659? +
How do I check if I'm vulnerable to CVE-2024-2659? +
Related Vulnerabilities
Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate input, allowing specially crafted …
An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the product’s web …
3onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to execute arbitrary shell commands in the context …
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the adm.cgi binary's reboot_time function that …
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the makeRequest.cgi binary that allows unauthenticated …
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the internet.cgi binary that allows unauthenticated …