5.9

CVE-2023-29056

A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined.

Data is provided by the National Vulnerability Database (NVD)
LenovoThinkagile Hx5530 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx5530 Version-
LenovoThinkagile Hx7530 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx7530 Version-
LenovoThinkagile Vx3331 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Vx3331 Version-
LenovoThinkagile Hx Enclosure Firmware Version < 3.72_tei388s
   LenovoThinkagile Hx Enclosure Version-
LenovoThinkagile Hx1021 Firmware Version < 3.72_tei388s
   LenovoThinkagile Hx1021 Version-
LenovoThinkagile Hx1320 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx1320 Version-
LenovoThinkagile Hx1321 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx1321 Version-
LenovoThinkagile Hx1331 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx1331 Version-
LenovoThinkagile Hx1520-r Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx1520-r Version-
LenovoThinkagile Hx1521-r Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx1521-r Version-
LenovoThinkagile Hx2320-e Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx2320-e Version-
LenovoThinkagile Hx2321 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx2321 Version-
LenovoThinkagile Hx2330 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx2330 Version-
LenovoThinkagile Hx2330 Firmware Version2.93_afbt30p
   LenovoThinkagile Hx2330 Version-
LenovoThinkagile Hx2331 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx2331 Version-
LenovoThinkagile Hx2720-e Firmware Version < 3.72_tei388s
   LenovoThinkagile Hx2720-e Version-
LenovoThinkagile Hx3320 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx3320 Version-
LenovoThinkagile Hx3321 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx3321 Version-
LenovoThinkagile Hx3330 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx3330 Version-
LenovoThinkagile Hx3331 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx3331 Version-
LenovoThinkagile Hx3331 Firmware Version < 4.71_d8bt48p
   LenovoThinkagile Hx3331 Version-
LenovoThinkagile Hx3375 Firmware Version < 4.71_d8bt48p
   LenovoThinkagile Hx3375 Version-
LenovoThinkagile Hx3376 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx3376 Version-
LenovoThinkagile Hx3520-g Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx3520-g Version-
LenovoThinkagile Hx3521-g Firmware Version < 3.72_tei388s
   LenovoThinkagile Hx3521-g Version-
LenovoThinkagile Hx3720 Firmware Version < 3.72_tei388s
   LenovoThinkagile Hx3720 Version-
LenovoThinkagile Hx3721 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx3721 Version-
LenovoThinkagile Hx5520 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx5520 Version-
LenovoThinkagile Hx5520-c Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx5520-c Version-
LenovoThinkagile Hx5521 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx5521 Version-
LenovoThinkagile Hx5521-c Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx5521-c Version-
LenovoThinkagile Hx5531 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx5531 Version-
LenovoThinkagile Hx7520 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx7520 Version-
LenovoThinkagile Hx7521 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx7521 Version-
LenovoThinkagile Hx7530 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx7530 Version-
LenovoThinkagile Hx7531 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx7531 Version-
LenovoThinkagile Hx7531 Firmware Version < 2.75_psi348s
   LenovoThinkagile Hx7531 Version-
LenovoThinkagile Hx7820 Firmware Version < 2.75_psi348s
   LenovoThinkagile Hx7820 Version-
LenovoThinkagile Hx7821 Firmware Version < 3.72_tei388s
   LenovoThinkagile Hx7821 Version-
LenovoThinkagile Mx1020 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Mx1020 Version-
LenovoThinkagile Mx3330-f Firmware Version < 2.93_afbt30p
   LenovoThinkagile Mx3330-f Version-
LenovoThinkagile Mx3330-h Firmware Version < 2.93_afbt30p
   LenovoThinkagile Mx3330-h Version-
LenovoThinkagile Mx3331-f Firmware Version < 2.93_afbt30p
   LenovoThinkagile Mx3331-f Version-
LenovoThinkagile Mx3331-h Firmware Version < 2.93_afbt30p
   LenovoThinkagile Mx3331-h Version-
LenovoThinkagile Mx3530 F Firmware Version < 2.93_afbt30p
   LenovoThinkagile Mx3530 F Version-
LenovoThinkagile Mx3530-h Firmware Version < 2.93_afbt30p
   LenovoThinkagile Mx3530-h Version-
LenovoThinkagile Mx3531 H Firmware Version < 2.93_afbt30p
   LenovoThinkagile Mx3531 H Version-
LenovoThinkagile Mx3531-f Firmware Version < 3.72_tei388s
   LenovoThinkagile Mx3531-f Version-
LenovoThinkagile Mx1021 On Se350 Firmware Version < 3.72_tei388s
LenovoThinkagile Vx 1se Firmware Version < 3.72_tei388s
   LenovoThinkagile Vx 1se Version-
LenovoThinkagile Vx 2u4n Firmware Version < 3.72_tei388s
   LenovoThinkagile Vx 2u4n Version-
LenovoThinkagile Vx 4u Firmware Version < 2.75_psi348s
   LenovoThinkagile Vx 4u Version-
LenovoThinkagile Vx1320 Firmware Version < 3.72_tei388s
   LenovoThinkagile Vx1320 Version-
LenovoThinkagile Vx2320 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Vx2320 Version-
LenovoThinkagile Vx2330 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Vx2330 Version-
LenovoThinkagile Vx3320 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Vx3320 Version-
LenovoThinkagile Vx3330 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Vx3330 Version-
LenovoThinkagile Vx3520-g Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Vx3520-g Version-
LenovoThinkagile Vx3530-g Firmware Version < 2.93_afbt30p
   LenovoThinkagile Vx3530-g Version-
LenovoThinkagile Vx3720 Firmware Version < 3.72_tei388s
   LenovoThinkagile Vx3720 Version-
LenovoThinkagile Vx5520 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Vx5520 Version-
LenovoThinkagile Vx5530 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Vx5530 Version-
LenovoThinkagile Vx7320 N Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Vx7320 N Version-
LenovoThinkagile Vx7330 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Vx7330 Version-
LenovoThinkagile Vx7520 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Vx7520 Version-
LenovoThinkagile Vx7520 N Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Vx7520 N Version-
LenovoThinkagile Vx7530 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Vx7530 Version-
LenovoThinkagile Vx7531 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Vx7531 Version-
LenovoThinkagile Vx7820 Firmware Version < 2.75_psi348s
   LenovoThinkagile Vx7820 Version-
LenovoThinkedge Se450 Firmware Version < 1.60_usx324o
   LenovoThinkedge Se450 Version-
LenovoThinkstation P920 Firmware Version < 8.88_cdi3a4a
   LenovoThinkstation P920 Version-
LenovoThinksystem Sd530 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sd530 Version-
LenovoThinksystem Sd630 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem Sd630 V2 Version-
LenovoThinksystem Sd650 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sd650 Version-
LenovoThinksystem Sd650 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem Sd650 V2 Version-
LenovoThinksystem Sd650-n V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem Sd650-n V2 Version-
LenovoThinksystem Se350 Firmware Version < 3.72_tei388s
   LenovoThinksystem Se350 Version-
LenovoThinksystem Sn550 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sn550 Version-
LenovoThinksystem Sn550 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem Sn550 V2 Version-
LenovoThinksystem Sn850 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sn850 Version-
LenovoThinksystem Sr150 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sr150 Version-
LenovoThinksystem Sr158 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sr158 Version-
LenovoThinksystem Sr250 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sr250 Version-
LenovoThinksystem Sr250 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem Sr250 V2 Version-
LenovoThinksystem Sr258 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sr258 Version-
LenovoThinksystem Sr258 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem Sr258 V2 Version-
LenovoThinksystem Sr530 Firmware Version < 8.88_cdi3a4a
   LenovoThinksystem Sr530 Version-
LenovoThinksystem Sr550 Firmware Version < 8.88_cdi3a4a
   LenovoThinksystem Sr550 Version-
LenovoThinksystem Sr570 Firmware Version < 8.88_cdi3a4a
   LenovoThinksystem Sr570 Version-
LenovoThinksystem Sr590 Firmware Version < 8.88_cdi3a4a
   LenovoThinksystem Sr590 Version-
LenovoThinksystem Sr630 Firmware Version < 8.88_cdi3a4a
   LenovoThinksystem Sr630 Version-
LenovoThinksystem Sr630 V2 Firmware Version < 2.93_afbt30p
   LenovoThinksystem Sr630 V2 Version-
LenovoThinksystem Sr645 Firmware Version < 4.71_d8bt48p
   LenovoThinksystem Sr645 Version-
LenovoThinksystem Sr645 V3 Firmware Version < 4.71_d8bt48p
   LenovoThinksystem Sr645 V3 Version-
LenovoThinksystem Sr650 Firmware Version < 8.88_cdi3a4a
   LenovoThinksystem Sr650 Version-
LenovoThinksystem Sr650 V2 Firmware Version < 2.93_afbt30p
   LenovoThinksystem Sr650 V2 Version-
LenovoThinksystem Sr665 Firmware Version < 4.71_d8bt48p
   LenovoThinksystem Sr665 Version-
LenovoThinksystem Sr665 V3 Firmware Version < 4.71_d8bt48p
   LenovoThinksystem Sr665 V3 Version-
LenovoThinksystem Sr670 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sr670 Version-
LenovoThinksystem Sr670 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem Sr670 V2 Version-
LenovoThinksystem Sr850 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sr850 Version-
LenovoThinksystem Sr850 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem Sr850 V2 Version-
LenovoThinksystem Sr850p Firmware Version < 3.72_tei388s
   LenovoThinksystem Sr850p Version-
LenovoThinksystem Sr860 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sr860 Version-
LenovoThinksystem Sr860 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem Sr860 V2 Version-
LenovoThinksystem Sr950 Firmware Version < 2.75_psi348s
   LenovoThinksystem Sr950 Version-
LenovoThinksystem St250 Firmware Version < 3.72_tei388s
   LenovoThinksystem St250 Version-
LenovoThinksystem St250 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem St250 V2 Version-
LenovoThinksystem St258 Firmware Version < 3.72_tei388s
   LenovoThinksystem St258 Version-
LenovoThinksystem St258 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem St258 V2 Version-
LenovoThinksystem St550 Firmware Version < 8.88_cdi3a4a
   LenovoThinksystem St550 Version-
LenovoThinksystem St650 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem St650 V2 Version-
LenovoThinksystem St658 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem St658 V2 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.15% 0.368
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
psirt@lenovo.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.