Vulnerabilities > Lenovo > Thinkagile Mx1021 ON Se350 Firmware
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-10-25 | CVE-2023-4607 | Improper Privilege Management vulnerability in Lenovo products An authenticated XCC user can change permissions for any user through a crafted API command. | 8.8 |
2023-05-01 | CVE-2023-0683 | Unspecified vulnerability in Lenovo products A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call. | 8.8 |
2023-05-01 | CVE-2023-25492 | Use of Externally-Controlled Format String vulnerability in Lenovo products A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format string injection vulnerability in a web interface API. | 8.8 |
2023-04-28 | CVE-2023-25495 | Insufficiently Protected Credentials vulnerability in Lenovo products A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. | 4.9 |
2023-04-28 | CVE-2023-29056 | Unspecified vulnerability in Lenovo products A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. | 5.9 |
2023-04-28 | CVE-2023-29057 | Unspecified vulnerability in Lenovo products A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. | 8.8 |
2023-04-28 | CVE-2023-29058 | Unspecified vulnerability in Lenovo products A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. | 6.5 |