CVE-2023-4606
—CVSS 3.1
8.1 high
EPSS
<1%p38
Published
()
Modified
Description
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
- Vendors
- lenovo
- Products
- thinkagile hx5530 firmware, thinkagile hx7530 firmware, thinkagile vx3331 firmware, thinkagile hx1331 firmware, thinkagile hx2330 firmware, thinkagile hx2331 firmware, thinkagile hx3330 firmware, thinkagile hx3331 firmware, thinkagile hx3375 firmware, thinkagile hx3376 firmware, thinkagile hx5531 firmware, thinkagile hx7531 firmware
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.