Thinkagile Mx3330 F All Flash Firmware
by Lenovo
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-4606 | Hig | 0.53 | 8.1 | 0.00 | Oct 25, 2023 | An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected. | ||
| CVE-2023-4607 | Hig | 0.49 | 7.5 | 0.00 | Oct 25, 2023 | An authenticated XCC user can change permissions for any user through a crafted API command. | ||
| CVE-2022-40137 | Med | 0.44 | 6.7 | 0.00 | Jan 30, 2023 | A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code. | ||
| CVE-2023-4608 | Med | 0.27 | 4.1 | 0.00 | Oct 25, 2023 | An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected. |
- risk 0.53cvss 8.1epss 0.00
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
- risk 0.49cvss 7.5epss 0.00
An authenticated XCC user can change permissions for any user through a crafted API command.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
- risk 0.27cvss 4.1epss 0.00
An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.