CVE-2024-21935CWE-241

Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate Redfish® API commands to remove files…

Medium · published September 23, 2025

CVSS v3.1
5.0
EPSS
0%
Percentile
11.8
In the wild
Unconfirmed
What it is

Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate Redfish® API commands to remove files from the local root directory, potentially resulting in data corruption.

The record
Technical detail
CVSS v3.1
5.0 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00215 · 11.8th percentile
Weakness
CWE-241 · Improper Handling of Unexpected Data Type
Published
2025-09-23T21:38Z
EPSS history
Timeline
  • 23 SEP 21:38Z
    Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate Redfish® API commands to remove files…
    cvelistv5