Thinksystem Sd650 Dwc Dual Node Tray Firmware
by Lenovo
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-4607 | Hig | 0.49 | 7.5 | 0.00 | Oct 25, 2023 | An authenticated XCC user can change permissions for any user through a crafted API command. | ||
| CVE-2022-40134 | Med | 0.29 | 4.4 | 0.00 | Jan 30, 2023 | An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. |
- risk 0.49cvss 7.5epss 0.00
An authenticated XCC user can change permissions for any user through a crafted API command.
- risk 0.29cvss 4.4epss 0.00
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.