CVE-2023-29057
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/04/2023
Last modified:
10/05/2023
Description
A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentication/authorization and logins configured as “Local First, then LDAP”.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:lenovo:thinkagile_hx5530_firmware:*:*:*:*:*:*:*:* | 2.93_afbt30p (excluding) | |
| cpe:2.3:h:lenovo:thinkagile_hx5530:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkagile_hx7530_firmware:*:*:*:*:*:*:*:* | 2.93_afbt30p (excluding) | |
| cpe:2.3:h:lenovo:thinkagile_hx7530:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkagile_vx3331_firmware:*:*:*:*:*:*:*:* | 2.93_afbt30p (excluding) | |
| cpe:2.3:h:lenovo:thinkagile_vx3331:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkagile_hx_enclosure_firmware:*:*:*:*:*:*:*:* | 3.72_tei388s (excluding) | |
| cpe:2.3:h:lenovo:thinkagile_hx_enclosure:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkagile_hx1021_firmware:*:*:*:*:*:*:*:* | 3.72_tei388s (excluding) | |
| cpe:2.3:h:lenovo:thinkagile_hx1021:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkagile_hx1320_firmware:*:*:*:*:*:*:*:* | 8.88_cdi3a4a (excluding) | |
| cpe:2.3:h:lenovo:thinkagile_hx1320:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkagile_hx1321_firmware:*:*:*:*:*:*:*:* | 8.88_cdi3a4a (excluding) | |
| cpe:2.3:h:lenovo:thinkagile_hx1321:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkagile_hx1331_firmware:*:*:*:*:*:*:*:* | 2.93_afbt30p (excluding) |
To consult the complete list of CPE names with products and versions, see this page



