IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, and FW1060.00 through FW1060.10 has static credentials which may allow network users to gain service privileges to the FSP.
History

Tue, 29 Oct 2024 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Oct 2024 01:00:00 +0000

Type Values Removed Values Added
Description IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, and FW1060.00 through FW1060.10 has static credentials which may allow network users to gain service privileges to the FSP.
Title IBM Flexible Service Processor hard coded credentials
First Time appeared Ibm
Ibm power9 System Firmware
Weaknesses CWE-798
CPEs cpe:2.3:o:ibm:power9_system_firmware:fw1030.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power9_system_firmware:fw1050.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power9_system_firmware:fw1060.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power9_system_firmware:fw860.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power9_system_firmware:fw950.00:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm power9 System Firmware
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2024-10-29T00:37:16.004Z

Updated: 2024-11-02T03:55:32.353Z

Reserved: 2024-09-03T13:50:26.296Z

Link: CVE-2024-45656

cve-icon Vulnrichment

Updated: 2024-10-29T12:49:47.731Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-29T01:15:03.823

Modified: 2024-10-29T14:34:04.427

Link: CVE-2024-45656

cve-icon Redhat

No data.