Description
A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions.
Related CPE's
o
lenovo
thinkagile_hx7530_firmware
h
lenovo
thinkagile_hx7530
o
lenovo
thinkagile_hx2330_firmware
o
lenovo
thinkagile_hx3331_firmware
h
lenovo
thinkagile_hx3331
o
lenovo
thinkagile_hx7531_firmware
h
lenovo
thinkagile_hx7531
References
https://support.lenovo.com/us/en/product_security/LEN-118321
https://support.lenovo.com/us/en/product_security/LEN-118321
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:H
6.4 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2023-04-28T19:15:08.750Z
2 years agoLast modified
2024-11-21T06:56:28.387Z
1 year ago