Unrated severityNVD Advisory· Published Oct 24, 2023· Updated Sep 11, 2024
CVE-2023-4606
CVE-2023-4606
Description
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.
This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
Affected products
1- Range: various
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.