CVE-2023-4606

An authenticated XCC user with Read-Only permission can change a different users password through a crafted API command.

This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
lenovoCNA
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
VendorProductVersion
lenovothinkagile_hx5530_firmware
-
lenovothinkagile_hx7530_firmware
-
lenovothinkagile_vx3331_firmware
-
lenovothinkagile_hx1331_firmware
-
lenovothinkagile_hx2330_firmware
-
lenovothinkagile_hx2331_firmware
-
lenovothinkagile_hx3330_firmware
-
lenovothinkagile_hx3331_firmware
-
lenovothinkagile_hx3331_firmware
-
lenovothinkagile_hx3375_firmware
-
lenovothinkagile_hx3376_firmware
-
lenovothinkagile_hx5531_firmware
-
lenovothinkagile_hx7530_firmware
-
lenovothinkagile_hx7531_firmware
-
lenovothinkagile_hx7531_firmware
-
lenovothinkagile_mx3330-f_all-flash_firmware
-
lenovothinkagile_mx3330-h_hybrid_firmware
-
lenovothinkagile_mx3331-f_all-flash_firmware
-
lenovothinkagile_mx3331-h_hybrid_firmware
-
lenovothinkagile_mx3530_f_all_flash_firmware
-
lenovothinkagile_mx3530-h_hybrid_firmware
-
lenovothinkagile_mx3531_h_hybrid_firmware
-
lenovothinkagile_mx3531-f_all-flash_firmware
-
lenovothinkagile_vx2330_firmware
-
lenovothinkagile_vx3330_firmware
-
lenovothinkagile_vx3530-g_firmware
-
lenovothinkagile_vx5530_firmware
-
lenovothinkagile_vx7330_firmware
-
lenovothinkagile_vx7530_firmware
-
lenovothinkagile_vx7531_firmware
-
lenovothinksystem_sd630_v2_firmware
-
lenovothinksystem_sd650_v2_firmware
-
lenovothinksystem_sd650_v3_firmware
-
lenovothinksystem_sd650-n_v2_firmware
-
lenovothinksystem_sd665_v3_firmware
-
lenovothinksystem_sn550_v2_firmware
-
lenovothinksystem_sr250_firmware
-
lenovothinksystem_sr258_v2_firmware
-
lenovothinksystem_sr630_v2_firmware
-
lenovothinksystem_sr630_v3_firmware
-
lenovothinksystem_sr635_v3_firmware
-
lenovothinksystem_sr645_firmware
-
lenovothinksystem_sr645_v3_firmware
-
lenovothinksystem_sr650_v2_firmware
-
lenovothinksystem_sr650_v3_firmware
-
lenovothinksystem_sr655_v3_firmware
-
lenovothinksystem_sr665_firmware
-
lenovothinksystem_sr665_v3_firmware
-
lenovothinksystem_sr670_firmware
-
lenovothinksystem_sr670_v2_firmware
-
lenovothinksystem_sr675_v3_firmware
-
lenovothinksystem_sr850_v2_firmware
-
lenovothinksystem_sr850_v2_firmware
-
lenovothinksystem_sr850_v3_firmware
-
lenovothinksystem_sr860_v2_firmware
-
lenovothinksystem_sr860_v2_firmware
-
lenovothinksystem_sr860_v3_firmware
-
lenovothinksystem_st250_v2_firmware
-
lenovothinksystem_st258_v2_firmware
-
lenovothinksystem_st650_v2_firmware
-
lenovothinksystem_st650_v3_firmware
-
lenovothinksystem_st658_v2_firmware
-
lenovothinksystem_st658_v3_firmware
-
𝑥
= Vulnerable software versions