CVE-2023-29058
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/04/2023
Last modified:
08/05/2023
Description
A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:lenovo:thinkagile_hx5530_firmware:*:*:*:*:*:*:*:* | 2.93_afbt30p (excluding) | |
| cpe:2.3:h:lenovo:thinkagile_hx5530:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkagile_hx7530_firmware:*:*:*:*:*:*:*:* | 2.93_afbt30p (excluding) | |
| cpe:2.3:h:lenovo:thinkagile_hx7530:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkagile_vx3331_firmware:*:*:*:*:*:*:*:* | 2.93_afbt30p (excluding) | |
| cpe:2.3:h:lenovo:thinkagile_vx3331:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkagile_hx_enclosure_firmware:*:*:*:*:*:*:*:* | 3.72_tei388s (excluding) | |
| cpe:2.3:h:lenovo:thinkagile_hx_enclosure:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkagile_hx1021_firmware:*:*:*:*:*:*:*:* | 3.72_tei388s (excluding) | |
| cpe:2.3:h:lenovo:thinkagile_hx1021:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkagile_hx1320_firmware:*:*:*:*:*:*:*:* | 8.88_cdi3a4a (excluding) | |
| cpe:2.3:h:lenovo:thinkagile_hx1320:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkagile_hx1321_firmware:*:*:*:*:*:*:*:* | 8.88_cdi3a4a (excluding) | |
| cpe:2.3:h:lenovo:thinkagile_hx1321:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lenovo:thinkagile_hx1331_firmware:*:*:*:*:*:*:*:* | 2.93_afbt30p (excluding) |
To consult the complete list of CPE names with products and versions, see this page



