No analysis available yet.
Vendor Solution
Customers should update to the version (or later) of Lenovo XClarity Controller (XCC) identified in the related Lenovo Product Security Advisory: https://support.lenovo.com/us/en/product_security/LEN-118321 https://support.lenovo.com/us/en/product_security/LEN-118321
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-32661 | A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions. |
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-118321 |
|
Thu, 30 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2025-01-30T18:49:28.930Z
Reserved: 2023-03-30T12:46:45.646Z
Link: CVE-2023-29058
Updated: 2024-08-02T14:00:15.529Z
Status : Modified
Published: 2023-04-28T21:15:08.750
Modified: 2024-11-21T07:56:28.387
Link: CVE-2023-29058
No data.
OpenCVE Enrichment
No data.
EUVD