CVE-2023-25492

Severity CVSS v4.0:
Pending analysis
Type:
CWE-134 Format String Vulnerability
Publication date:
01/05/2023
Last modified:
10/05/2023

Description

A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format string injection vulnerability in a web interface API.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lenovo:thinkagile_hx5530_firmware:*:*:*:*:*:*:*:* 2.93_afbt30p (excluding)
cpe:2.3:h:lenovo:thinkagile_hx5530:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx7530_firmware:*:*:*:*:*:*:*:* 2.93_afbt30p (excluding)
cpe:2.3:h:lenovo:thinkagile_hx7530:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_vx3331_firmware:*:*:*:*:*:*:*:* 2.93_afbt30p (excluding)
cpe:2.3:h:lenovo:thinkagile_vx3331:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx_enclosure_firmware:*:*:*:*:*:*:*:* 3.72_tei388s (excluding)
cpe:2.3:h:lenovo:thinkagile_hx_enclosure:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx1021_firmware:*:*:*:*:*:*:*:* 3.72_tei388s (excluding)
cpe:2.3:h:lenovo:thinkagile_hx1021:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx1320_firmware:*:*:*:*:*:*:*:* 8.88_cdi3a4a (excluding)
cpe:2.3:h:lenovo:thinkagile_hx1320:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx1321_firmware:*:*:*:*:*:*:*:* 8.88_cdi3a4a (excluding)
cpe:2.3:h:lenovo:thinkagile_hx1321:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx1331_firmware:*:*:*:*:*:*:*:* 2.93_afbt30p (excluding)


References to Advisories, Solutions, and Tools