IBM FSP Vulnerability: Static Credentials May Allow Network Users to Gain Service Privileges

CVE-2024-45656
9.8CRITICAL

Key Information

Vendor
IBM
Status
Flexible Service Processor
Vendor
CVE Published:
29 October 2024

Summary

IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, and FW1060.00 through FW1060.10 has static credentials which may allow network users to gain service privileges to the FSP.

Affected Version(s)

Flexible Service Processor <= FW860.00

Flexible Service Processor <= FW950.00

Flexible Service Processor <= FW1030.00

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.