IBM Product Security Update Advisory (CVE-2024-45656)

Overview

 

An update has been released to address vulnerabilities in IBM Products. Users of the affected versions are advised to update to the latest version.

 

Affected Products

 

CVE-2024-45656

  • Server Firmware versions: FW1060.00 (inclusive) ~ FW1060.10 (inclusive)
  • Server Firmware versions: FW1050.00 (inclusive) ~ FW1050.21 (inclusive)
  • Server Firmware versions: FW1030.00 (inclusive) ~ FW1030.61 (inclusive)
  • Server Firmware versions: FW950.00 (inclusive) ~ FW950.C0 (inclusive)
  • Server Firmware versions: FW860.00 (inclusive) ~ FW860.B3 (inclusive)

 

 

Resolved Vulnerabilities

 

Vulnerability in IBM Flexible Service Processor (FSP) with static credentials, potentially allowing network users to gain service privileges (CVE-2024-45656)

 

Vulnerability Patches

 

Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-45656

  • Server Firmware version: FW1060.11 or later version
  • Server Firmware version: FW1050.22 or later version
  • Server Firmware version: FW1030.62 or later version
  • Server Firmware version: FW950.C1 or later version
  • Server Firmware version: FW860.B4 or later version

 

 

Referenced Sites

 

[1] Security Bulletin: This Power System update is being released to address CVE-2024-45656

https://www.ibm.com/support/pages/node/7174183