High severity7.2NVD Advisory· Published Apr 15, 2024· Updated Jun 17, 2026
CVE-2024-2659
CVE-2024-2659
Description
A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function.
Affected products
70- cpe:2.3:o:lenovo:nextscale_n1200_enclosure_firmware:*:*:*:*:*:*:*:*Range: <FHET62A-3.50
- cpe:2.3:o:lenovo:thinkagile_2u4n_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_cp-cb-10_firmware:*:*:*:*:*:*:*:*Range: <TESM40B-1.27
- cpe:2.3:o:lenovo:thinkagile_cp-cb-10e_firmware:*:*:*:*:*:*:*:*Range: <TESM40B-1.27
- cpe:2.3:o:lenovo:thinkagile_hx1021_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx1321_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx1331_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx1521-r_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx2321_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx2331_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx3321_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx3331_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx3376_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx3521-g_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx3721_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx5521-c_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx5521_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx5531_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx630_v3_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx645_v3_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx650_v3_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx665_v3_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx7521_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx7531_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx7821_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx_e1_enclosure_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx_e2_enclosure_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_hx_enclosure_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx1320_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx2320_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx2330_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx2375_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx3320_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx3330_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx3331_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx3375_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx3376_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx3520-g_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx3530-g_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx3575-g_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx3720_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx5520_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx5530_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx5575_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx630_v3_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx630_v4_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx635_v3_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx645_v3_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx650_v3_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx650_v4_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx655_v3_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx665_v3_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx7320-n_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx7330-n_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx7375-n_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx7520_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx7530_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx7531_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx7575_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx7820_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx850_v3_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx_1se_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx_1u_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx_2u_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinkagile_vx_4u_firmware:*:*:*:*:*:*:*:*Range: <tesm40b-1.27
- cpe:2.3:o:lenovo:thinksystem_d2_enclosure_firmware:*:*:*:*:*:*:*:*Range: <TESM40B-1.27
- cpe:2.3:o:lenovo:thinksystem_da240_firmware:*:*:*:*:*:*:*:*Range: <UMSM12I-1.1.3
- cpe:2.3:o:lenovo:thinksystem_dw612_firmware:*:*:*:*:*:*:*:*Range: <UMSM12I-1.1.3
(expand)+ 1 more
- (no CPE)
- (no CPE)range: various
Patches
Vulnerability mechanics
References
1- support.lenovo.com/us/en/product_security/LEN-140420nvdVendor Advisory
News mentions
0No linked articles in our index yet.