CVE-2023-4608
25.10.2023, 18:17
An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
Vendor | Product | Version |
---|---|---|
lenovo | thinkagile_hx5530_firmware | - |
lenovo | thinkagile_hx7530_firmware | - |
lenovo | thinkagile_vx3331_firmware | - |
lenovo | thinkagile_hx1331_firmware | - |
lenovo | thinkagile_hx2330_firmware | - |
lenovo | thinkagile_hx2331_firmware | - |
lenovo | thinkagile_hx3330_firmware | - |
lenovo | thinkagile_hx3331_firmware | - |
lenovo | thinkagile_hx3331_firmware | - |
lenovo | thinkagile_hx3375_firmware | - |
lenovo | thinkagile_hx3376_firmware | - |
lenovo | thinkagile_hx5531_firmware | - |
lenovo | thinkagile_hx7530_firmware | - |
lenovo | thinkagile_hx7531_firmware | - |
lenovo | thinkagile_hx7531_firmware | - |
lenovo | thinkagile_mx3330-f_all-flash_firmware | - |
lenovo | thinkagile_mx3330-h_hybrid_firmware | - |
lenovo | thinkagile_mx3331-f_all-flash_firmware | - |
lenovo | thinkagile_mx3331-h_hybrid_firmware | - |
lenovo | thinkagile_mx3530_f_all_flash_firmware | - |
lenovo | thinkagile_mx3530-h_hybrid_firmware | - |
lenovo | thinkagile_mx3531_h_hybrid_firmware | - |
lenovo | thinkagile_mx3531-f_all-flash_firmware | - |
lenovo | thinkagile_vx2330_firmware | - |
lenovo | thinkagile_vx3330_firmware | - |
lenovo | thinkagile_vx3530-g_firmware | - |
lenovo | thinkagile_vx5530_firmware | - |
lenovo | thinkagile_vx7330_firmware | - |
lenovo | thinkagile_vx7530_firmware | - |
lenovo | thinkagile_vx7531_firmware | - |
lenovo | thinksystem_sd630_v2_firmware | - |
lenovo | thinksystem_sd650_v2_firmware | - |
lenovo | thinksystem_sd650_v3_firmware | - |
lenovo | thinksystem_sd650-n_v2_firmware | - |
lenovo | thinksystem_sd665_v3_firmware | - |
lenovo | thinksystem_sn550_v2_firmware | - |
lenovo | thinksystem_sr250_firmware | - |
lenovo | thinksystem_sr258_v2_firmware | - |
lenovo | thinksystem_sr630_v2_firmware | - |
lenovo | thinksystem_sr630_v3_firmware | - |
lenovo | thinksystem_sr635_v3_firmware | - |
lenovo | thinksystem_sr645_firmware | - |
lenovo | thinksystem_sr645_v3_firmware | - |
lenovo | thinksystem_sr650_v2_firmware | - |
lenovo | thinksystem_sr650_v3_firmware | - |
lenovo | thinksystem_sr655_v3_firmware | - |
lenovo | thinksystem_sr665_firmware | - |
lenovo | thinksystem_sr665_v3_firmware | - |
lenovo | thinksystem_sr670_firmware | - |
lenovo | thinksystem_sr670_v2_firmware | - |
lenovo | thinksystem_sr675_v3_firmware | - |
lenovo | thinksystem_sr850_v2_firmware | - |
lenovo | thinksystem_sr850_v2_firmware | - |
lenovo | thinksystem_sr850_v3_firmware | - |
lenovo | thinksystem_sr860_v2_firmware | - |
lenovo | thinksystem_sr860_v2_firmware | - |
lenovo | thinksystem_sr860_v3_firmware | - |
lenovo | thinksystem_st250_v2_firmware | - |
lenovo | thinksystem_st258_v2_firmware | - |
lenovo | thinksystem_st650_v2_firmware | - |
lenovo | thinksystem_st650_v3_firmware | - |
lenovo | thinksystem_st658_v2_firmware | - |
lenovo | thinksystem_st658_v3_firmware | - |
𝑥
= Vulnerable software versions