ZeroHour

CVE-2023-29058

CVSS 3.1
6.5 medium
EPSS
<1%p29
Published
()
Modified
Description

A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions.

Vendors
lenovo
Products
thinkagile hx5530 firmware, thinkagile hx7530 firmware, thinkagile vx3331 firmware, thinkagile hx enclosure firmware, thinkagile hx1021 firmware, thinkagile hx1320 firmware, thinkagile hx1321 firmware, thinkagile hx1331 firmware, thinkagile hx1520-r firmware, thinkagile hx1521-r firmware, thinkagile hx2320-e firmware, thinkagile hx2321 firmware
Weakness
CWE-276
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.