CVE-2024-2659

HIGH
Published Apr 15, 2024 Modified Jul 28, 2025 CWE-78

Description

A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function.

Is your site exposed to CVE-2024-2659?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

7.2
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weakness Type (CWE)

CWE-78 OS Command Injection

Affected Products

Vendor Product
lenovo nextscale_n1200_enclosure_firmware
lenovo nextscale_n1200_enclosure
lenovo thinkagile_cp-cb-10_firmware
lenovo thinkagile_cp-cb-10
lenovo thinkagile_cp-cb-10e_firmware
lenovo thinkagile_cp-cb-10e
lenovo thinkagile_hx_enclosure_firmware
lenovo thinkagile_hx_enclosure
lenovo thinkagile_hx3721_firmware
lenovo thinkagile_hx3721
lenovo thinkagile_hx1021_firmware
lenovo thinkagile_hx1021
lenovo thinkagile_hx_e1_enclosure_firmware
lenovo thinkagile_hx_e1_enclosure
lenovo thinkagile_hx_e2_enclosure_firmware
lenovo thinkagile_hx_e2_enclosure
lenovo thinkagile_hx1321_firmware
lenovo thinkagile_hx1321
lenovo thinkagile_hx2321_firmware
lenovo thinkagile_hx2321
lenovo thinkagile_hx3321_firmware
lenovo thinkagile_hx3321
lenovo thinkagile_hx1331_firmware
lenovo thinkagile_hx1331
lenovo thinkagile_hx2331_firmware
lenovo thinkagile_hx2331
lenovo thinkagile_hx3331_firmware
lenovo thinkagile_hx3331
lenovo thinkagile_hx630_v3_firmware
lenovo thinkagile_hx630_v3
lenovo thinkagile_hx3376_firmware
lenovo thinkagile_hx3376
lenovo thinkagile_hx645_v3_firmware
lenovo thinkagile_hx645_v3
lenovo thinkagile_hx1521-r_firmware
lenovo thinkagile_hx1521-r
lenovo thinkagile_hx3521-g_firmware
lenovo thinkagile_hx3521-g
lenovo thinkagile_hx5521_firmware
lenovo thinkagile_hx5521
lenovo thinkagile_hx5521-c_firmware
lenovo thinkagile_hx5521-c
lenovo thinkagile_hx7521_firmware
lenovo thinkagile_hx7521
lenovo thinkagile_hx5531_firmware
lenovo thinkagile_hx5531
lenovo thinkagile_hx7531_firmware
lenovo thinkagile_hx7531
lenovo thinkagile_hx650_v3_firmware
lenovo thinkagile_hx650_v3
lenovo thinkagile_hx665_v3_firmware
lenovo thinkagile_hx665_v3
lenovo thinkagile_hx7821_firmware
lenovo thinkagile_hx7821
lenovo thinkagile_vx3720_firmware
lenovo thinkagile_vx3720
lenovo thinkagile_2u4n_firmware
lenovo thinkagile_2u4n
lenovo thinkagile_vx1320_firmware
lenovo thinkagile_vx1320
lenovo thinkagile_vx_1se_firmware
lenovo thinkagile_vx_1se
lenovo thinkagile_vx3320_firmware
lenovo thinkagile_vx3320
lenovo thinkagile_vx2320_firmware
lenovo thinkagile_vx2320
lenovo thinkagile_vx7320-n_firmware
lenovo thinkagile_vx7320-n
lenovo thinkagile_vx_1u_firmware
lenovo thinkagile_vx_1u
lenovo thinkagile_vx2330_firmware
lenovo thinkagile_vx2330
lenovo thinkagile_vx3330_firmware
lenovo thinkagile_vx3330
lenovo thinkagile_vx7330-n_firmware
lenovo thinkagile_vx7330-n
lenovo thinkagile_vx3331_firmware
lenovo thinkagile_vx3331
lenovo thinkagile_vx630_v3_firmware
lenovo thinkagile_vx630_v3
lenovo thinkagile_vx630_v4_firmware
lenovo thinkagile_vx630_v4
lenovo thinkagile_vx635_v3_firmware
lenovo thinkagile_vx635_v3
lenovo thinkagile_vx2375_firmware
lenovo thinkagile_vx2375
lenovo thinkagile_vx3375_firmware
lenovo thinkagile_vx3375
lenovo thinkagile_vx7375-n_firmware
lenovo thinkagile_vx7375-n
lenovo thinkagile_vx3376_firmware
lenovo thinkagile_vx3376
lenovo thinkagile_vx645_v3_firmware
lenovo thinkagile_vx645_v3
lenovo thinkagile_vx5520_firmware
lenovo thinkagile_vx5520
lenovo thinkagile_vx7520_firmware
lenovo thinkagile_vx7520
lenovo thinkagile_vx3520-g_firmware
lenovo thinkagile_vx3520-g
lenovo thinkagile_vx5520_firmware
lenovo thinkagile_vx5520
lenovo thinkagile_vx_2u_firmware
lenovo thinkagile_vx_2u
lenovo thinkagile_vx3530-g_firmware
lenovo thinkagile_vx3530-g
lenovo thinkagile_vx5530_firmware
lenovo thinkagile_vx5530
lenovo thinkagile_vx7530_firmware
lenovo thinkagile_vx7530
lenovo thinkagile_vx7531_firmware
lenovo thinkagile_vx7531
lenovo thinkagile_vx650_v3_firmware
lenovo thinkagile_vx650_v3
lenovo thinkagile_vx650_v4_firmware
lenovo thinkagile_vx650_v4
lenovo thinkagile_vx655_v3_firmware
lenovo thinkagile_vx655_v3
lenovo thinkagile_vx5575_firmware
lenovo thinkagile_vx5575
lenovo thinkagile_vx7575_firmware
lenovo thinkagile_vx7575
lenovo thinkagile_vx3575-g_firmware
lenovo thinkagile_vx3575-g
lenovo thinkagile_vx665_v3_firmware
lenovo thinkagile_vx665_v3
lenovo thinkagile_vx850_v3_firmware
lenovo thinkagile_vx850_v3
lenovo thinkagile_vx_4u_firmware
lenovo thinkagile_vx_4u
lenovo thinkagile_vx7820_firmware
lenovo thinkagile_vx7820
lenovo thinksystem_d2_enclosure_firmware
lenovo thinksystem_d2_enclosure
lenovo thinksystem_da240_firmware
lenovo thinksystem_da240
lenovo thinksystem_dw612_firmware
lenovo thinksystem_dw612

References

Frequently Asked Questions

What is CVE-2024-2659? +
A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function. It has a CVSS v3.1 base score of 7.2 (HIGH).
How severe is CVE-2024-2659? +
CVE-2024-2659 has a CVSS v3.1 score of 7.2 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2024-2659? +
CVE-2024-2659 affects products from lenovo, specifically: nextscale_n1200_enclosure, nextscale_n1200_enclosure_firmware, thinkagile_2u4n, thinkagile_2u4n_firmware, thinkagile_cp-cb-10, thinkagile_cp-cb-10_firmware, thinkagile_cp-cb-10e, thinkagile_cp-cb-10e_firmware, thinkagile_hx1021, thinkagile_hx1021_firmware, thinkagile_hx1321, thinkagile_hx1321_firmware, thinkagile_hx1331, thinkagile_hx1331_firmware, thinkagile_hx1521-r, thinkagile_hx1521-r_firmware, thinkagile_hx2321, thinkagile_hx2321_firmware, thinkagile_hx2331, thinkagile_hx2331_firmware, thinkagile_hx3321, thinkagile_hx3321_firmware, thinkagile_hx3331, thinkagile_hx3331_firmware, thinkagile_hx3376, thinkagile_hx3376_firmware, thinkagile_hx3521-g, thinkagile_hx3521-g_firmware, thinkagile_hx3721, thinkagile_hx3721_firmware, thinkagile_hx5521, thinkagile_hx5521-c, thinkagile_hx5521-c_firmware, thinkagile_hx5521_firmware, thinkagile_hx5531, thinkagile_hx5531_firmware, thinkagile_hx630_v3, thinkagile_hx630_v3_firmware, thinkagile_hx645_v3, thinkagile_hx645_v3_firmware, thinkagile_hx650_v3, thinkagile_hx650_v3_firmware, thinkagile_hx665_v3, thinkagile_hx665_v3_firmware, thinkagile_hx7521, thinkagile_hx7521_firmware, thinkagile_hx7531, thinkagile_hx7531_firmware, thinkagile_hx7821, thinkagile_hx7821_firmware, thinkagile_hx_e1_enclosure, thinkagile_hx_e1_enclosure_firmware, thinkagile_hx_e2_enclosure, thinkagile_hx_e2_enclosure_firmware, thinkagile_hx_enclosure, thinkagile_hx_enclosure_firmware, thinkagile_vx1320, thinkagile_vx1320_firmware, thinkagile_vx2320, thinkagile_vx2320_firmware, thinkagile_vx2330, thinkagile_vx2330_firmware, thinkagile_vx2375, thinkagile_vx2375_firmware, thinkagile_vx3320, thinkagile_vx3320_firmware, thinkagile_vx3330, thinkagile_vx3330_firmware, thinkagile_vx3331, thinkagile_vx3331_firmware, thinkagile_vx3375, thinkagile_vx3375_firmware, thinkagile_vx3376, thinkagile_vx3376_firmware, thinkagile_vx3520-g, thinkagile_vx3520-g_firmware, thinkagile_vx3530-g, thinkagile_vx3530-g_firmware, thinkagile_vx3575-g, thinkagile_vx3575-g_firmware, thinkagile_vx3720, thinkagile_vx3720_firmware, thinkagile_vx5520, thinkagile_vx5520_firmware, thinkagile_vx5530, thinkagile_vx5530_firmware, thinkagile_vx5575, thinkagile_vx5575_firmware, thinkagile_vx630_v3, thinkagile_vx630_v3_firmware, thinkagile_vx630_v4, thinkagile_vx630_v4_firmware, thinkagile_vx635_v3, thinkagile_vx635_v3_firmware, thinkagile_vx645_v3, thinkagile_vx645_v3_firmware, thinkagile_vx650_v3, thinkagile_vx650_v3_firmware, thinkagile_vx650_v4, thinkagile_vx650_v4_firmware, thinkagile_vx655_v3, thinkagile_vx655_v3_firmware, thinkagile_vx665_v3, thinkagile_vx665_v3_firmware, thinkagile_vx7320-n, thinkagile_vx7320-n_firmware, thinkagile_vx7330-n, thinkagile_vx7330-n_firmware, thinkagile_vx7375-n, thinkagile_vx7375-n_firmware, thinkagile_vx7520, thinkagile_vx7520_firmware, thinkagile_vx7530, thinkagile_vx7530_firmware, thinkagile_vx7531, thinkagile_vx7531_firmware, thinkagile_vx7575, thinkagile_vx7575_firmware, thinkagile_vx7820, thinkagile_vx7820_firmware, thinkagile_vx850_v3, thinkagile_vx850_v3_firmware, thinkagile_vx_1se, thinkagile_vx_1se_firmware, thinkagile_vx_1u, thinkagile_vx_1u_firmware, thinkagile_vx_2u, thinkagile_vx_2u_firmware, thinkagile_vx_4u, thinkagile_vx_4u_firmware, thinksystem_d2_enclosure, thinksystem_d2_enclosure_firmware, thinksystem_da240, thinksystem_da240_firmware, thinksystem_dw612, thinksystem_dw612_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-2659? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-2659 — free, no signup required.