CVE-2023-4606 — Missing Authorization in Lenovo Xclarity Controller
Severity
8.1HIGHNVD
EPSS
0.1%
top 69.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 25
Description
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.
This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HExploitability: 2.8 | Impact: 5.2
Affected Packages1 packages
🔴Vulnerability Details
2GHSA▶
GHSA-fm9p-5c8h-mw8h: An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command↗2023-10-25
CVEList▶
CVE-2023-4606: An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command↗2023-10-24