9.8

CVE-2024-45656

IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, and FW1060.00 through FW1060.10 has static credentials which may allow network users to gain service privileges to the FSP.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmPower System E1080 (9080-hex) Firmware Version >= FW1030.00 <= FW1030.61
IbmPower System E1080 (9080-hex) Firmware Version >= FW1050.00 <= FW1050.21
IbmPower System E1080 (9080-hex) Firmware Version >= FW1060.00 <= FW1060.10
IbmPower System L922 (9008-22l) Firmware Version >= FW950.00 <= FW950.C0
IbmPower System S922 (9009-22a) Firmware Version >= FW950.00 <= FW950.C0
IbmPower System S922 (9009-22g) Firmware Version >= FW950.00 <= FW950.C0
   IbmPower System S922 (9009-22g) Version-
IbmPower System H922 (9223-22h) Firmware Version >= FW950.00 <= FW950.C0
IbmPower System H922 (9223-22s) Firmware Version >= FW950.00 <= FW950.C0
   IbmPower System H922 (9223-22s) Version-
IbmPower System S914 (9009-41a) Firmware Version >= FW950.00 <= FW950.C0
IbmPower System S914 (9009-41g) Firmware Version >= FW950.00 <= FW950.C0
   IbmPower System S914 (9009-41g) Version-
IbmPower System S924 (9009-42a) Firmware Version >= FW950.00 <= FW950.C0
IbmPower System S924 (9009-42g) Firmware Version >= FW950.00 <= FW950.C0
   IbmPower System S924 (9009-42g) Version-
IbmPower System H924 (9223-42h) Firmware Version >= FW950.00 <= FW950.C0
IbmPower System H924 (9223-42s) Firmware Version >= FW950.00 <= FW950.C0
   IbmPower System H924 (9223-42s) Version-
IbmPower System E950 (9040-mr9) Firmware Version >= FW950.00 <= FW950.C0
   IbmPower System E950 (9040-mr9) Version-
IbmPower System E980 (9080-m9s) Firmware Version >= FW950.00 <= FW950.C0
   IbmPower System E980 (9080-m9s) Version-
IbmEss 5000 (5105-22e) Firmware Version >= FW950.00 <= FW950.C0
   IbmEss 5000 (5105-22e) Version-
IbmPower System S812 (8284-21a) Firmware Version >= FW860.00 <= FW860.B3
   IbmPower System S812 (8284-21a) Version-
IbmPower System S822 (8284-22a) Firmware Version >= FW860.00 <= FW860.B3
   IbmPower System S822 (8284-22a) Version-
IbmPower System S814 (8286-41a) Firmware Version >= FW860.00 <= FW860.B3
   IbmPower System S814 (8286-41a) Version-
IbmPower System S824 (8286-42a) Firmware Version >= FW860.00 <= FW860.B3
   IbmPower System S824 (8286-42a) Version-
IbmPower System S812l (8247-21l) Firmware Version >= FW860.00 <= FW860.B3
IbmPower System S822l (8247-22l) Firmware Version >= FW860.00 <= FW860.B3
IbmPower System S824l (8247-42l) Firmware Version >= FW860.00 <= FW860.B3
IbmPower System E850 (8408-e8e) Firmware Version >= FW860.00 <= FW860.B3
   IbmPower System E850 (8408-e8e) Version-
IbmPower System E850c (8408-44e) Firmware Version >= FW860.00 <= FW860.B3
IbmPower System E870 (9119-mme) Firmware Version >= FW860.00 <= FW860.B3
   IbmPower System E870 (9119-mme) Version-
IbmPower System E880 (9119-mhe) Firmware Version >= FW860.00 <= FW860.B3
   IbmPower System E880 (9119-mhe) Version-
IbmPower System E870c (9080-mme) Firmware Version >= FW860.00 <= FW860.B3
IbmPower System E880c (9080-mhe) Firmware Version >= FW860.00 <= FW860.B3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.11% 0.306
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@us.ibm.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.