CVE-2023-29057
published 2023-04-28CVE-2023-29057: A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege…
high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentication/authorization and logins configured as “Local First, then LDAP”.
Affected
113 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lenovo | thinkagile_hx1021_firmware | < 3.72_tei388s | 3.72_tei388s |
| lenovo | thinkagile_hx1320_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx1321_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx1331_firmware | < 2.93_afbt30p | 2.93_afbt30p |
| lenovo | thinkagile_hx1520-r_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx1521-r_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx2320-e_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx2321_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx2330_firmware | < 2.93_afbt30p | 2.93_afbt30p |
| lenovo | thinkagile_hx2330_firmware | — | — |
| lenovo | thinkagile_hx2331_firmware | < 2.93_afbt30p | 2.93_afbt30p |
| lenovo | thinkagile_hx2720-e_firmware | < 3.72_tei388s | 3.72_tei388s |
| lenovo | thinkagile_hx3320_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx3321_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx3330_firmware | < 2.93_afbt30p | 2.93_afbt30p |
| lenovo | thinkagile_hx3331_firmware | < 2.93_afbt30p | 2.93_afbt30p |
| lenovo | thinkagile_hx3331_firmware | < 4.71_d8bt48p | 4.71_d8bt48p |
| lenovo | thinkagile_hx3375_firmware | < 4.71_d8bt48p | 4.71_d8bt48p |
| lenovo | thinkagile_hx3376_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx3520-g_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx3521-g_firmware | < 3.72_tei388s | 3.72_tei388s |
| lenovo | thinkagile_hx3720_firmware | < 3.72_tei388s | 3.72_tei388s |
| lenovo | thinkagile_hx3721_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx5520-c_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |
| lenovo | thinkagile_hx5520_firmware | < 8.88_cdi3a4a | 8.88_cdi3a4a |