ZeroHour

CVE-2023-4607

CVSS 3.1
8.8 high
EPSS
<1%p36
Published
()
Modified
Description

An authenticated XCC user can change permissions for any user through a crafted API command.

Vendors
lenovo
Products
thinkagile hx5530 firmware, thinkagile hx7530 firmware, thinkagile vx3331 firmware, thinkagile hx1331 firmware, thinkagile hx2330 firmware, thinkagile hx2331 firmware, thinkagile hx3330 firmware, thinkagile hx3331 firmware, thinkagile hx3375 firmware, thinkagile hx3376 firmware, thinkagile hx5531 firmware, thinkagile hx7531 firmware
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.