VYPR

Thinkagile Mx3330 H Hybrid Firmware

by Lenovo

CVEs (4)

  • CVE-2023-4606HigOct 25, 2023
    risk 0.53cvss 8.1epss 0.00

    An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.

  • CVE-2023-4607HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.00

    An authenticated XCC user can change permissions for any user through a crafted API command.

  • CVE-2022-40137MedJan 30, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2023-4608MedOct 25, 2023
    risk 0.27cvss 4.1epss 0.00

    An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.  This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.