ZeroHour

CVE-2023-4606

CVSS 3.1
8.1 high
EPSS
<1%p38
Published
()
Modified
Description

An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.

Vendors
lenovo
Products
thinkagile hx5530 firmware, thinkagile hx7530 firmware, thinkagile vx3331 firmware, thinkagile hx1331 firmware, thinkagile hx2330 firmware, thinkagile hx2331 firmware, thinkagile hx3330 firmware, thinkagile hx3331 firmware, thinkagile hx3375 firmware, thinkagile hx3376 firmware, thinkagile hx5531 firmware, thinkagile hx7531 firmware
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.