8.8

CVE-2023-29057

A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentication/authorization and logins configured as “Local First, then LDAP”.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LenovoThinkagile Hx5530 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx5530 Version-
LenovoThinkagile Hx7530 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx7530 Version-
LenovoThinkagile Vx3331 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Vx3331 Version-
LenovoThinkagile Hx Enclosure Firmware Version < 3.72_tei388s
   LenovoThinkagile Hx Enclosure Version-
LenovoThinkagile Hx1021 Firmware Version < 3.72_tei388s
   LenovoThinkagile Hx1021 Version-
LenovoThinkagile Hx1320 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx1320 Version-
LenovoThinkagile Hx1321 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx1321 Version-
LenovoThinkagile Hx1331 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx1331 Version-
LenovoThinkagile Hx1520-r Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx1520-r Version-
LenovoThinkagile Hx1521-r Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx1521-r Version-
LenovoThinkagile Hx2320-e Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx2320-e Version-
LenovoThinkagile Hx2321 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx2321 Version-
LenovoThinkagile Hx2330 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx2330 Version-
LenovoThinkagile Hx2330 Firmware Version2.93_afbt30p
   LenovoThinkagile Hx2330 Version-
LenovoThinkagile Hx2331 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx2331 Version-
LenovoThinkagile Hx2720-e Firmware Version < 3.72_tei388s
   LenovoThinkagile Hx2720-e Version-
LenovoThinkagile Hx3320 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx3320 Version-
LenovoThinkagile Hx3321 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx3321 Version-
LenovoThinkagile Hx3330 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx3330 Version-
LenovoThinkagile Hx3331 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx3331 Version-
LenovoThinkagile Hx3331 Firmware Version < 4.71_d8bt48p
   LenovoThinkagile Hx3331 Version-
LenovoThinkagile Hx3375 Firmware Version < 4.71_d8bt48p
   LenovoThinkagile Hx3375 Version-
LenovoThinkagile Hx3376 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx3376 Version-
LenovoThinkagile Hx3520-g Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx3520-g Version-
LenovoThinkagile Hx3521-g Firmware Version < 3.72_tei388s
   LenovoThinkagile Hx3521-g Version-
LenovoThinkagile Hx3720 Firmware Version < 3.72_tei388s
   LenovoThinkagile Hx3720 Version-
LenovoThinkagile Hx3721 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx3721 Version-
LenovoThinkagile Hx5520 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx5520 Version-
LenovoThinkagile Hx5520-c Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx5520-c Version-
LenovoThinkagile Hx5521 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx5521 Version-
LenovoThinkagile Hx5521-c Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx5521-c Version-
LenovoThinkagile Hx5531 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx5531 Version-
LenovoThinkagile Hx7520 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Hx7520 Version-
LenovoThinkagile Hx7521 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx7521 Version-
LenovoThinkagile Hx7530 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx7530 Version-
LenovoThinkagile Hx7531 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Hx7531 Version-
LenovoThinkagile Hx7531 Firmware Version < 2.75_psi348s
   LenovoThinkagile Hx7531 Version-
LenovoThinkagile Hx7820 Firmware Version < 2.75_psi348s
   LenovoThinkagile Hx7820 Version-
LenovoThinkagile Hx7821 Firmware Version < 3.72_tei388s
   LenovoThinkagile Hx7821 Version-
LenovoThinkagile Mx1020 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Mx1020 Version-
LenovoThinkagile Mx3330-f Firmware Version < 2.93_afbt30p
   LenovoThinkagile Mx3330-f Version-
LenovoThinkagile Mx3330-h Firmware Version < 2.93_afbt30p
   LenovoThinkagile Mx3330-h Version-
LenovoThinkagile Mx3331-f Firmware Version < 2.93_afbt30p
   LenovoThinkagile Mx3331-f Version-
LenovoThinkagile Mx3331-h Firmware Version < 2.93_afbt30p
   LenovoThinkagile Mx3331-h Version-
LenovoThinkagile Mx3530 F Firmware Version < 2.93_afbt30p
   LenovoThinkagile Mx3530 F Version-
LenovoThinkagile Mx3530-h Firmware Version < 2.93_afbt30p
   LenovoThinkagile Mx3530-h Version-
LenovoThinkagile Mx3531 H Firmware Version < 2.93_afbt30p
   LenovoThinkagile Mx3531 H Version-
LenovoThinkagile Mx3531-f Firmware Version < 3.72_tei388s
   LenovoThinkagile Mx3531-f Version-
LenovoThinkagile Mx1021 On Se350 Firmware Version < 3.72_tei388s
LenovoThinkagile Vx 1se Firmware Version < 3.72_tei388s
   LenovoThinkagile Vx 1se Version-
LenovoThinkagile Vx 2u4n Firmware Version < 3.72_tei388s
   LenovoThinkagile Vx 2u4n Version-
LenovoThinkagile Vx 4u Firmware Version < 2.75_psi348s
   LenovoThinkagile Vx 4u Version-
LenovoThinkagile Vx1320 Firmware Version < 3.72_tei388s
   LenovoThinkagile Vx1320 Version-
LenovoThinkagile Vx2320 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Vx2320 Version-
LenovoThinkagile Vx2330 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Vx2330 Version-
LenovoThinkagile Vx3320 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Vx3320 Version-
LenovoThinkagile Vx3330 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Vx3330 Version-
LenovoThinkagile Vx3520-g Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Vx3520-g Version-
LenovoThinkagile Vx3530-g Firmware Version < 2.93_afbt30p
   LenovoThinkagile Vx3530-g Version-
LenovoThinkagile Vx3720 Firmware Version < 3.72_tei388s
   LenovoThinkagile Vx3720 Version-
LenovoThinkagile Vx5520 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Vx5520 Version-
LenovoThinkagile Vx5530 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Vx5530 Version-
LenovoThinkagile Vx7320 N Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Vx7320 N Version-
LenovoThinkagile Vx7330 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Vx7330 Version-
LenovoThinkagile Vx7520 Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Vx7520 Version-
LenovoThinkagile Vx7520 N Firmware Version < 8.88_cdi3a4a
   LenovoThinkagile Vx7520 N Version-
LenovoThinkagile Vx7530 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Vx7530 Version-
LenovoThinkagile Vx7531 Firmware Version < 2.93_afbt30p
   LenovoThinkagile Vx7531 Version-
LenovoThinkagile Vx7820 Firmware Version < 2.75_psi348s
   LenovoThinkagile Vx7820 Version-
LenovoThinkedge Se450 Firmware Version < 1.60_usx324o
   LenovoThinkedge Se450 Version-
LenovoThinkstation P920 Firmware Version < 8.88_cdi3a4a
   LenovoThinkstation P920 Version-
LenovoThinksystem Sd530 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sd530 Version-
LenovoThinksystem Sd630 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem Sd630 V2 Version-
LenovoThinksystem Sd650 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sd650 Version-
LenovoThinksystem Sd650 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem Sd650 V2 Version-
LenovoThinksystem Sd650-n V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem Sd650-n V2 Version-
LenovoThinksystem Se350 Firmware Version < 3.72_tei388s
   LenovoThinksystem Se350 Version-
LenovoThinksystem Sn550 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sn550 Version-
LenovoThinksystem Sn550 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem Sn550 V2 Version-
LenovoThinksystem Sn850 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sn850 Version-
LenovoThinksystem Sr150 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sr150 Version-
LenovoThinksystem Sr158 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sr158 Version-
LenovoThinksystem Sr250 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sr250 Version-
LenovoThinksystem Sr250 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem Sr250 V2 Version-
LenovoThinksystem Sr258 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sr258 Version-
LenovoThinksystem Sr258 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem Sr258 V2 Version-
LenovoThinksystem Sr530 Firmware Version < 8.88_cdi3a4a
   LenovoThinksystem Sr530 Version-
LenovoThinksystem Sr550 Firmware Version < 8.88_cdi3a4a
   LenovoThinksystem Sr550 Version-
LenovoThinksystem Sr570 Firmware Version < 8.88_cdi3a4a
   LenovoThinksystem Sr570 Version-
LenovoThinksystem Sr590 Firmware Version < 8.88_cdi3a4a
   LenovoThinksystem Sr590 Version-
LenovoThinksystem Sr630 Firmware Version < 8.88_cdi3a4a
   LenovoThinksystem Sr630 Version-
LenovoThinksystem Sr630 V2 Firmware Version < 2.93_afbt30p
   LenovoThinksystem Sr630 V2 Version-
LenovoThinksystem Sr645 Firmware Version < 4.71_d8bt48p
   LenovoThinksystem Sr645 Version-
LenovoThinksystem Sr645 V3 Firmware Version < 4.71_d8bt48p
   LenovoThinksystem Sr645 V3 Version-
LenovoThinksystem Sr650 Firmware Version < 8.88_cdi3a4a
   LenovoThinksystem Sr650 Version-
LenovoThinksystem Sr650 V2 Firmware Version < 2.93_afbt30p
   LenovoThinksystem Sr650 V2 Version-
LenovoThinksystem Sr665 Firmware Version < 4.71_d8bt48p
   LenovoThinksystem Sr665 Version-
LenovoThinksystem Sr665 V3 Firmware Version < 4.71_d8bt48p
   LenovoThinksystem Sr665 V3 Version-
LenovoThinksystem Sr670 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sr670 Version-
LenovoThinksystem Sr670 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem Sr670 V2 Version-
LenovoThinksystem Sr850 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sr850 Version-
LenovoThinksystem Sr850 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem Sr850 V2 Version-
LenovoThinksystem Sr850p Firmware Version < 3.72_tei388s
   LenovoThinksystem Sr850p Version-
LenovoThinksystem Sr860 Firmware Version < 3.72_tei388s
   LenovoThinksystem Sr860 Version-
LenovoThinksystem Sr860 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem Sr860 V2 Version-
LenovoThinksystem Sr950 Firmware Version < 2.75_psi348s
   LenovoThinksystem Sr950 Version-
LenovoThinksystem St250 Firmware Version < 3.72_tei388s
   LenovoThinksystem St250 Version-
LenovoThinksystem St250 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem St250 V2 Version-
LenovoThinksystem St258 Firmware Version < 3.72_tei388s
   LenovoThinksystem St258 Version-
LenovoThinksystem St258 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem St258 V2 Version-
LenovoThinksystem St550 Firmware Version < 8.88_cdi3a4a
   LenovoThinksystem St550 Version-
LenovoThinksystem St650 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem St650 V2 Version-
LenovoThinksystem St658 V2 Firmware Version < 2.60_tgbt42h
   LenovoThinksystem St658 V2 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.313
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
psirt@lenovo.com 7.3 2.1 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.