CVE-2023-25492
published 2023-05-01CVE-2023-25492: A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format string…
PriorityP349high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.51%
40.0th percentile
A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format string injection vulnerability in a web interface API.
Affected
113 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lenovo | thinkagile_hx1021_firmware | < 3.72_tei388s | 3.72_tei388s |
| lenovo | thinkagile_hx1320_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx1321_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx1331_firmware | < 2.93_afbt30p | 2.93_afbt30p |
| lenovo | thinkagile_hx1520-r_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx1521-r_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx2320-e_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx2321_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx2330_firmware | < 2.93_afbt30p | 2.93_afbt30p |
| lenovo | thinkagile_hx2330_firmware | — | — |
| lenovo | thinkagile_hx2331_firmware | < 2.93_afbt30p | 2.93_afbt30p |
| lenovo | thinkagile_hx2720-e_firmware | < 3.72_tei388s | 3.72_tei388s |
| lenovo | thinkagile_hx3320_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx3321_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx3330_firmware | < 2.93_afbt30p | 2.93_afbt30p |
| lenovo | thinkagile_hx3331_firmware | < 2.93_afbt30p | 2.93_afbt30p |
| lenovo | thinkagile_hx3331_firmware | < 4.71_d8bt48p | 4.71_d8bt48p |
| lenovo | thinkagile_hx3375_firmware | < 4.71_d8bt48p | 4.71_d8bt48p |
| lenovo | thinkagile_hx3376_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx3520-g_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx3521-g_firmware | < 3.72_tei388s | 3.72_tei388s |
| lenovo | thinkagile_hx3720_firmware | < 3.72_tei388s | 3.72_tei388s |
| lenovo | thinkagile_hx3721_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx5520-c_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx5520_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-01
Published