Vulnerabilities > Lenovo > Thinksystem Sd650 DWC Dual Node Tray Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-10-25 CVE-2023-4607 Unspecified vulnerability in Lenovo products
An authenticated XCC user can change permissions for any user through a crafted API command.
network
low complexity
lenovo
8.8
2023-01-30 CVE-2022-40134 Out-of-bounds Read vulnerability in Lenovo products
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
local
low complexity
lenovo CWE-125
4.4