Description


A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format string injection vulnerability in a web interface API.

Related CPE's




o

lenovo

thinkagile_hx7530_firmware

2

h

lenovo

thinkagile_hx7530

2





















o

lenovo

thinkagile_hx2330_firmware

2












o

lenovo

thinkagile_hx3331_firmware

2

h

lenovo

thinkagile_hx3331

2



























o

lenovo

thinkagile_hx7531_firmware

2

h

lenovo

thinkagile_hx7531

2
























































































































































Weaknesses



CWE-134


CWE-134

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.8 · High

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2023-05-01T15:15:09.290

2 years ago

Last modified

2023-05-10T13:37:50.410

1 year ago