ZeroHour

CVE-2023-25492

CVSS 3.1
8.8 high
EPSS
<1%p42
Published
()
Modified
Description

A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format string injection vulnerability in a web interface API.

Vendors
lenovo
Products
thinkagile hx5530 firmware, thinkagile hx7530 firmware, thinkagile vx3331 firmware, thinkagile hx enclosure firmware, thinkagile hx1021 firmware, thinkagile hx1320 firmware, thinkagile hx1321 firmware, thinkagile hx1331 firmware, thinkagile hx1520-r firmware, thinkagile hx1521-r firmware, thinkagile hx2320-e firmware, thinkagile hx2321 firmware
Weakness
CWE-134
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.