Cyber Resilience

CVE-2024-23591

Lenovo Thinksystem Sr670 V2 Firmware ≤ u8e126i-2.20

Published
16 February 2024
Modified
17 June 2026
Patch / advisory
CVSS Score v3.1 2.0
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
EPSS Score 0.0016 6th percentile
Risk Priority 19 floored blend · peak EPSS

Summary

CVE-2024-23591 is a low-severity Product Released in Non-Release Configuration (CWE-1269) vulnerability in Lenovo Thinksystem Sr670 V2 Firmware. Its CVSS base score is 2.0 (Low).

Operationally, exploitation aligns with the MITRE ATT&CK technique Valid Accounts (T1078); ranked at the 6th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to CM-2 (Baseline Configuration) and CM-6 (Configuration Settings) — see the control section below for these in your framework.

EU & UK References

Vulnerability Data

ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which could allow an attacker with privileged logical access to the host or physical access to server internals to modify or disable Intel Boot…

more

Guard firmware integrity, SPS security, and other SPS configuration setting. The server’s NIST SP 800-193-compliant Platform Firmware Resiliency (PFR) security subsystem significantly mitigates this issue.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise Techniques

T1078 Valid Accounts Stealth
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
T1078.001 Default Accounts Stealth
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
T1133 External Remote Services Persistence
Adversaries may leverage external-facing remote services to initially access and/or persist within a network.
T1552 Unsecured Credentials Credential Access
Adversaries may search compromised systems to find and obtain insecurely stored credentials.
T1552.001 Credentials In Files Credential Access
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials.
T1552.004 Private Keys Credential Access
Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials.
Derived from this CVE’s CWE(s) via the direct CWE→ATT&CK cross-walk.

CVEs Like This One

CVE-2023-5457Shared CWE-1269
CVE-2023-25495Same product: Lenovo Thinksystem Sr670 V2
CVE-2023-4608Same product: Lenovo Thinksystem Sr670 V2
CVE-2025-2503Same vendor: Lenovo
CVE-2023-43574Same vendor: Lenovo
CVE-2023-43572Same vendor: Lenovo
CVE-2023-34418Same vendor: Lenovo
CVE-2025-6230Same vendor: Lenovo
CVE-2023-4606Same product: Lenovo Thinksystem Sr670 V2
CVE-2023-5080Same vendor: Lenovo

Affected Assets

lenovo
thinksystem sr670 v2 firmware
≤ u8e126i-2.20

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)
  • 6 hardening rules · 5 OS baselines
Validate
Prove the fix (OWASP ASVS)

Mitigating Controls (NIST 800-53 r5) AI

Baseline configuration defines the approved production settings and prevents shipment while still in manufacturing or debug mode.

Establishing and enforcing the most restrictive configuration settings ensures the released product uses hardened production values.

Developer configuration management requires tracking and controlling the transition from manufacturing to release configuration.

Developer testing and evaluation can discover that the delivered build remains in a pre-production configuration.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-01 mostly match
prevents

Configuration management with hardened baselines directly prevents shipping pre-production or debug builds.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

degrades

Configuration management directly prevents release of non-release builds by enforcing approved, documented configurations.

finds

Security testing and acceptance criteria can detect and block deployment of pre-production builds.

prevents

Change-management procedures ensure only approved, release-ready configurations are deployed.

degrades

Controlling software installation on operational systems reduces the chance that pre-production builds reach production.

prevents

Secure development life-cycle practices include release-gate checks that catch non-release configurations.

mitigates

Separation of development, test and production environments prevents accidental promotion of non-release configurations.

Hardening callouts derived

Configuration rules from DISA STIG baselines that bear on weaknesses of the type cited by this CVE. Each rule is shown with the relationship its mapping actually records, against the CWE it was authored against. Derived via CVE→CWE over `controls_xwalks` (authoritative rows only; rows rated `none` are excluded).

Oracle Linux 8 (1 rule)
  • V-248521 OL 8 must be a vendor-supported release. prevents CWE-1269
RHEL 7 (1 rule)
  • V-204458 The Red Hat Enterprise Linux operating system must be a vendor supported release. prevents CWE-1269

References