CVE-2023-25495

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
28/04/2023
Last modified:
09/05/2023

Description

A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configured

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lenovo:thinkagile_hx5530_firmware:*:*:*:*:*:*:*:* 2.93_afbt30p (excluding)
cpe:2.3:h:lenovo:thinkagile_hx5530:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx7530_firmware:*:*:*:*:*:*:*:* 2.93_afbt30p (excluding)
cpe:2.3:h:lenovo:thinkagile_hx7530:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_vx3331_firmware:*:*:*:*:*:*:*:* 2.93_afbt30p (excluding)
cpe:2.3:h:lenovo:thinkagile_vx3331:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx_enclosure_firmware:*:*:*:*:*:*:*:* 3.72_tei388s (excluding)
cpe:2.3:h:lenovo:thinkagile_hx_enclosure:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx1021_firmware:*:*:*:*:*:*:*:* 3.72_tei388s (excluding)
cpe:2.3:h:lenovo:thinkagile_hx1021:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx1320_firmware:*:*:*:*:*:*:*:* 8.88_cdi3a4a (excluding)
cpe:2.3:h:lenovo:thinkagile_hx1320:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx1321_firmware:*:*:*:*:*:*:*:* 8.88_cdi3a4a (excluding)
cpe:2.3:h:lenovo:thinkagile_hx1321:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx1331_firmware:*:*:*:*:*:*:*:* 2.93_afbt30p (excluding)


References to Advisories, Solutions, and Tools