CVE-2023-4606

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/10/2023
Last modified:
07/11/2023

Description

An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.  <br /> <br /> This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lenovo:thinkagile_hx5530_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_hx5530:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx7530_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_hx7530:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_vx3331_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_vx3331:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx1331_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_hx1331:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx2330_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_hx2330:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx2331_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_hx2331:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx3330_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_hx3330:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx3331_firmware:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools