CVE-2024-23591CWE-1269

ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which could allow an attacker with…

Low · published February 16, 2024

CVSS v3.1
2.0
EPSS
0%
Percentile
5.7
In the wild
Unconfirmed
What it is

ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which could allow

an attacker with privileged logical access to the host or physical access to server internals to modify or disable Intel Boot Guard firmware integrity, SPS security, and other SPS configuration setting. The server’s NIST SP

800-193-compliant Platform Firmware Resiliency (PFR) security subsystem

significantly mitigates this issue.

The record
Technical detail
CVSS v3.1
2.0 · LOW
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00162 · 5.7th percentile
Weakness
CWE-1269 · Product Released in Non-Release Configuration
Published
2024-02-16T16:17Z
EPSS history
Timeline
  • 16 FEB 16:17Z
    ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which could allow an attacker with…
    cvelistv5