8.8

CVE-2023-4607

An authenticated XCC user can change permissions for any user through a crafted API command.

Data is provided by the National Vulnerability Database (NVD)
LenovoThinkagile Hx5530 Firmware Version-
   LenovoThinkagile Hx5530 Version-
LenovoThinkagile Hx7530 Firmware Version-
   LenovoThinkagile Hx7530 Version-
LenovoThinkagile Vx3331 Firmware Version-
   LenovoThinkagile Vx3331 Version-
LenovoThinkagile Hx1331 Firmware Version-
   LenovoThinkagile Hx1331 Version-
LenovoThinkagile Hx2330 Firmware Version-
   LenovoThinkagile Hx2330 Version-
LenovoThinkagile Hx2331 Firmware Version-
   LenovoThinkagile Hx2331 Version-
LenovoThinkagile Hx3330 Firmware Version-
   LenovoThinkagile Hx3330 Version-
LenovoThinkagile Hx3331 Firmware Version-
   LenovoThinkagile Hx3331 Version-
LenovoThinkagile Hx3331 Firmware Version-
   LenovoThinkagile Hx3331 Version-
LenovoThinkagile Hx3375 Firmware Version-
   LenovoThinkagile Hx3375 Version-
LenovoThinkagile Hx3376 Firmware Version-
   LenovoThinkagile Hx3376 Version-
LenovoThinkagile Hx5531 Firmware Version-
   LenovoThinkagile Hx5531 Version-
LenovoThinkagile Hx7530 Firmware Version-
   LenovoThinkagile Hx7530 Version-
LenovoThinkagile Hx7531 Firmware Version-
   LenovoThinkagile Hx7531 Version-
LenovoThinkagile Hx7531 Firmware Version-
   LenovoThinkagile Hx7531 Version-
LenovoThinkagile Vx2330 Firmware Version-
   LenovoThinkagile Vx2330 Version-
LenovoThinkagile Vx3330 Firmware Version-
   LenovoThinkagile Vx3330 Version-
LenovoThinkagile Vx5530 Firmware Version-
   LenovoThinkagile Vx5530 Version-
LenovoThinkagile Vx7330 Firmware Version-
   LenovoThinkagile Vx7330 Version-
LenovoThinkagile Vx7530 Firmware Version-
   LenovoThinkagile Vx7530 Version-
LenovoThinkagile Vx7531 Firmware Version-
   LenovoThinkagile Vx7531 Version-
LenovoThinksystem Sr645 Firmware Version-
   LenovoThinksystem Sr645 Version-
LenovoThinksystem Sr665 Firmware Version-
   LenovoThinksystem Sr665 Version-
LenovoThinksystem Sr670 Firmware Version-
   LenovoThinksystem Sr670 Version-
LenovoThinkagile Hx1320 Firmware Version-
   LenovoThinkagile Hx1320 Version-
LenovoThinkagile Hx1321 Firmware Version-
   LenovoThinkagile Hx1321 Version-
LenovoThinkagile Hx2321 Firmware Version-
   LenovoThinkagile Hx2321 Version-
LenovoThinkagile Hx3320 Firmware Version-
   LenovoThinkagile Hx3320 Version-
LenovoThinkagile Hx3321 Firmware Version-
   LenovoThinkagile Hx3321 Version-
LenovoThinkagile Hx3720 Firmware Version-
   LenovoThinkagile Hx3720 Version-
LenovoThinkagile Hx3721 Firmware Version-
   LenovoThinkagile Hx3721 Version-
LenovoThinkagile Hx5520 Firmware Version-
   LenovoThinkagile Hx5520 Version-
LenovoThinkagile Hx5521 Firmware Version-
   LenovoThinkagile Hx5521 Version-
LenovoThinkagile Hx7520 Firmware Version-
   LenovoThinkagile Hx7520 Version-
LenovoThinkagile Hx7521 Firmware Version-
   LenovoThinkagile Hx7521 Version-
LenovoThinkagile Hx7820 Firmware Version-
   LenovoThinkagile Hx7820 Version-
LenovoThinkagile Hx7821 Firmware Version-
   LenovoThinkagile Hx7821 Version-
LenovoThinkagile Vx 1se Firmware Version-
   LenovoThinkagile Vx 1se Version-
LenovoThinkagile Vx 4u Firmware Version-
   LenovoThinkagile Vx 4u Version-
LenovoThinkagile Vx1320 Firmware Version-
   LenovoThinkagile Vx1320 Version-
LenovoThinkagile Vx2320 Firmware Version-
   LenovoThinkagile Vx2320 Version-
LenovoThinkagile Vx3320 Firmware Version-
   LenovoThinkagile Vx3320 Version-
LenovoThinkagile Vx3720 Firmware Version-
   LenovoThinkagile Vx3720 Version-
LenovoThinkagile Vx5520 Firmware Version-
   LenovoThinkagile Vx5520 Version-
LenovoThinkagile Vx7520 Firmware Version-
   LenovoThinkagile Vx7520 Version-
LenovoThinkagile Vx7820 Firmware Version-
   LenovoThinkagile Vx7820 Version-
LenovoThinkedge Se450 Firmware Version-
   LenovoThinkedge Se450 Version-
LenovoThinksystem Sd530 Firmware Version-
   LenovoThinksystem Sd530 Version-
LenovoThinksystem Se350 Firmware Version-
   LenovoThinksystem Se350 Version-
LenovoThinksystem Se350 Firmware Version-
   LenovoThinksystem Se350 Version-
LenovoThinksystem Sn550 Firmware Version-
   LenovoThinksystem Sn550 Version-
LenovoThinksystem Sn550 Firmware Version-
   LenovoThinksystem Sn550 Version-
LenovoThinksystem Sn850 Firmware Version-
   LenovoThinksystem Sn850 Version-
LenovoThinksystem Sn850 Firmware Version-
   LenovoThinksystem Sn850 Version-
LenovoThinksystem Sr150 Firmware Version-
   LenovoThinksystem Sr150 Version-
LenovoThinksystem Sr158 Firmware Version-
   LenovoThinksystem Sr158 Version-
LenovoThinksystem Sr250 Firmware Version-
   LenovoThinksystem Sr250 Version-
LenovoThinksystem Sr258 Firmware Version-
   LenovoThinksystem Sr258 Version-
LenovoThinksystem Sr530 Firmware Version-
   LenovoThinksystem Sr530 Version-
LenovoThinksystem Sr550 Firmware Version-
   LenovoThinksystem Sr550 Version-
LenovoThinksystem Sr570 Firmware Version-
   LenovoThinksystem Sr570 Version-
LenovoThinksystem Sr590 Firmware Version-
   LenovoThinkserver Sr590 Version-
LenovoThinksystem Sr630 Firmware Version-
   LenovoThinksystem Sr630 Version-
LenovoThinksystem Sr650 Firmware Version-
   LenovoThinksystem Sr650 Version-
LenovoThinksystem Sr670 Firmware Version-
   LenovoThinksystem Sr670 Version-
LenovoThinksystem Sr850 Firmware Version-
   LenovoThinksystem Sr850 Version-
LenovoThinksystem Sr850 Firmware Version-
   LenovoThinksystem Sr850 Version-
LenovoThinksystem Sr860 Firmware Version-
   LenovoThinksystem Sr860 Version-
LenovoThinksystem Sr860 Firmware Version-
   LenovoThinksystem Sr860 Version-
LenovoThinksystem Sr950 Firmware Version-
   LenovoThinksystem Sr950 Version-
LenovoThinksystem St250 Firmware Version-
   LenovoThinksystem St250 Version-
LenovoThinksystem St258 Firmware Version-
   LenovoThinksystem St258 Version-
LenovoThinksystem St550 Firmware Version-
   LenovoThinksystem St550 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.13% 0.325
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
psirt@lenovo.com 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.