CVE-2023-25495
published 2023-04-28CVE-2023-25495: A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an…
PriorityP427medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.57%
43.1th percentile
A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configured
Affected
113 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lenovo | thinkagile_hx1021_firmware | < 3.72_tei388s | 3.72_tei388s |
| lenovo | thinkagile_hx1320_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx1321_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx1331_firmware | < 2.93_afbt30p | 2.93_afbt30p |
| lenovo | thinkagile_hx1520-r_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx1521-r_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx2320-e_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx2321_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx2330_firmware | < 2.93_afbt30p | 2.93_afbt30p |
| lenovo | thinkagile_hx2330_firmware | — | — |
| lenovo | thinkagile_hx2331_firmware | < 2.93_afbt30p | 2.93_afbt30p |
| lenovo | thinkagile_hx2720-e_firmware | < 3.72_tei388s | 3.72_tei388s |
| lenovo | thinkagile_hx3320_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx3321_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx3330_firmware | < 2.93_afbt30p | 2.93_afbt30p |
| lenovo | thinkagile_hx3331_firmware | < 2.93_afbt30p | 2.93_afbt30p |
| lenovo | thinkagile_hx3331_firmware | < 4.71_d8bt48p | 4.71_d8bt48p |
| lenovo | thinkagile_hx3375_firmware | < 4.71_d8bt48p | 4.71_d8bt48p |
| lenovo | thinkagile_hx3376_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx3520-g_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx3521-g_firmware | < 3.72_tei388s | 3.72_tei388s |
| lenovo | thinkagile_hx3720_firmware | < 3.72_tei388s | 3.72_tei388s |
| lenovo | thinkagile_hx3721_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx5520-c_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx5520_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-28
Published