Description
A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call.
Related CPE's
Vulnerable
o
lenovo
thinkagile_hx7530_firmware
2
h
lenovo
thinkagile_hx7530
2
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
o
lenovo
thinkagile_hx2330_firmware
2
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
o
lenovo
thinkagile_hx3331_firmware
2
h
lenovo
thinkagile_hx3331
2
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
o
lenovo
thinkagile_hx7531_firmware
2
h
lenovo
thinkagile_hx7531
2
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
Vulnerable
References
https://support.lenovo.com/us/en/product_security/LEN-99936
Vendor Advisory
https://support.lenovo.com/us/en/product_security/LEN-99936
Vendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
8.3 · High
Information
Source identifier
Vulnerability status
Modified
Published
2023-05-01T13:15:09.223Z
2 years agoLast modified
2024-11-21T06:37:37.157Z
1 year ago