This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
Metrics
No CVSS v4.0
Attack Vector Network
Attack Complexity High
Privileges Required High
Scope Unchanged
Confidentiality Impact Low
Integrity Impact Low
Availability Impact Low
User Interaction None
No CVSS v3.0
No CVSS v2
This CVE is not in the KEV list.
The EPSS score is 0.00095.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Lenovo
Subscribe
|
Thinkagile Hx1331
Subscribe
Thinkagile Hx1331 Firmware
Subscribe
Thinkagile Hx2330
Subscribe
Thinkagile Hx2330 Firmware
Subscribe
Thinkagile Hx2331
Subscribe
Thinkagile Hx2331 Firmware
Subscribe
Thinkagile Hx3330
Subscribe
Thinkagile Hx3330 Firmware
Subscribe
Thinkagile Hx3331
Subscribe
Thinkagile Hx3331 Firmware
Subscribe
Thinkagile Hx3375
Subscribe
Thinkagile Hx3375 Firmware
Subscribe
Thinkagile Hx3376
Subscribe
Thinkagile Hx3376 Firmware
Subscribe
Thinkagile Hx5530
Subscribe
Thinkagile Hx5530 Firmware
Subscribe
Thinkagile Hx5531
Subscribe
Thinkagile Hx5531 Firmware
Subscribe
Thinkagile Hx7530
Subscribe
Thinkagile Hx7530 Firmware
Subscribe
Thinkagile Hx7531
Subscribe
Thinkagile Hx7531 Firmware
Subscribe
Thinkagile Mx3330-f All-flash
Subscribe
Thinkagile Mx3330-f All-flash Firmware
Subscribe
Thinkagile Mx3330-h Hybrid
Subscribe
Thinkagile Mx3330-h Hybrid Firmware
Subscribe
Thinkagile Mx3331-f All-flash
Subscribe
Thinkagile Mx3331-f All-flash Firmware
Subscribe
Thinkagile Mx3331-h Hybrid
Subscribe
Thinkagile Mx3331-h Hybrid Firmware
Subscribe
Thinkagile Mx3530-h Hybrid
Subscribe
Thinkagile Mx3530-h Hybrid Firmware
Subscribe
Thinkagile Mx3530 F All Flash
Subscribe
Thinkagile Mx3530 F All Flash Firmware
Subscribe
Thinkagile Mx3531-f All-flash
Subscribe
Thinkagile Mx3531-f All-flash Firmware
Subscribe
Thinkagile Mx3531 H Hybrid
Subscribe
Thinkagile Mx3531 H Hybrid Firmware
Subscribe
Thinkagile Vx2330
Subscribe
Thinkagile Vx2330 Firmware
Subscribe
Thinkagile Vx3330
Subscribe
Thinkagile Vx3330 Firmware
Subscribe
Thinkagile Vx3331
Subscribe
Thinkagile Vx3331 Firmware
Subscribe
Thinkagile Vx3530-g
Subscribe
Thinkagile Vx3530-g Firmware
Subscribe
Thinkagile Vx5530
Subscribe
Thinkagile Vx5530 Firmware
Subscribe
Thinkagile Vx7330
Subscribe
Thinkagile Vx7330 Firmware
Subscribe
Thinkagile Vx7530
Subscribe
Thinkagile Vx7530 Firmware
Subscribe
Thinkagile Vx7531
Subscribe
Thinkagile Vx7531 Firmware
Subscribe
Thinksystem Sd630 V2
Subscribe
Thinksystem Sd630 V2 Firmware
Subscribe
Thinksystem Sd650-n V2
Subscribe
Thinksystem Sd650-n V2 Firmware
Subscribe
Thinksystem Sd650 V2
Subscribe
Thinksystem Sd650 V2 Firmware
Subscribe
Thinksystem Sd650 V3 Firmware
Subscribe
Thinksystem Sd665 V3 Firmware
Subscribe
Thinksystem Sn550 V2
Subscribe
Thinksystem Sn550 V2 Firmware
Subscribe
Thinksystem Sr250 Firmware
Subscribe
Thinksystem Sr250 V2
Subscribe
Thinksystem Sr258 V2
Subscribe
Thinksystem Sr258 V2 Firmware
Subscribe
Thinksystem Sr630 V2
Subscribe
Thinksystem Sr630 V2 Firmware
Subscribe
Thinksystem Sr630 V3 Firmware
Subscribe
Thinksystem Sr635 V3 Firmware
Subscribe
Thinksystem Sr645
Subscribe
Thinksystem Sr645 Firmware
Subscribe
Thinksystem Sr645 V3
Subscribe
Thinksystem Sr645 V3 Firmware
Subscribe
Thinksystem Sr650 V2
Subscribe
Thinksystem Sr650 V2 Firmware
Subscribe
Thinksystem Sr650 V3 Firmware
Subscribe
Thinksystem Sr655 V3 Firmware
Subscribe
Thinksystem Sr665
Subscribe
Thinksystem Sr665 Firmware
Subscribe
Thinksystem Sr665 V3 Firmware
Subscribe
Thinksystem Sr670
Subscribe
Thinksystem Sr670 Firmware
Subscribe
Thinksystem Sr670 V2
Subscribe
Thinksystem Sr670 V2 Firmware
Subscribe
Thinksystem Sr675 V3 Firmware
Subscribe
Thinksystem Sr850 V2
Subscribe
Thinksystem Sr850 V2 Firmware
Subscribe
Thinksystem Sr850 V3 Firmware
Subscribe
Thinksystem Sr860 V2
Subscribe
Thinksystem Sr860 V2 Firmware
Subscribe
Thinksystem Sr860 V3 Firmware
Subscribe
Thinksystem St250 V2
Subscribe
Thinksystem St250 V2 Firmware
Subscribe
Thinksystem St258 V2
Subscribe
Thinksystem St258 V2 Firmware
Subscribe
Thinksystem St650 V2
Subscribe
Thinksystem St650 V2 Firmware
Subscribe
Thinksystem St650 V3 Firmware
Subscribe
Thinksystem St658 V2
Subscribe
Thinksystem St658 V2 Firmware
Subscribe
Thinksystem St658 V3 Firmware
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
| AND |
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
| AND |
|
Configuration 10 [-]
| AND |
|
Configuration 11 [-]
| AND |
|
Configuration 12 [-]
| AND |
|
Configuration 13 [-]
| AND |
|
Configuration 14 [-]
| AND |
|
Configuration 15 [-]
| AND |
|
Configuration 16 [-]
| AND |
|
Configuration 17 [-]
| AND |
|
Configuration 18 [-]
| AND |
|
Configuration 19 [-]
| AND |
|
Configuration 20 [-]
| AND |
|
Configuration 21 [-]
| AND |
|
Configuration 22 [-]
| AND |
|
Configuration 23 [-]
| AND |
|
Configuration 24 [-]
| AND |
|
Configuration 25 [-]
| AND |
|
Configuration 26 [-]
| AND |
|
Configuration 27 [-]
| AND |
|
Configuration 28 [-]
| AND |
|
Configuration 29 [-]
| AND |
|
Configuration 30 [-]
| AND |
|
Configuration 31 [-]
| AND |
|
Configuration 32 [-]
| AND |
|
Configuration 33 [-]
|
Configuration 34 [-]
| AND |
|
Configuration 35 [-]
|
Configuration 36 [-]
| AND |
|
Configuration 37 [-]
| AND |
|
Configuration 38 [-]
| AND |
|
Configuration 39 [-]
| AND |
|
Configuration 40 [-]
|
Configuration 41 [-]
|
Configuration 42 [-]
| AND |
|
Configuration 43 [-]
| AND |
|
Configuration 44 [-]
| AND |
|
Configuration 45 [-]
|
Configuration 46 [-]
|
Configuration 47 [-]
| AND |
|
Configuration 48 [-]
|
Configuration 49 [-]
| AND |
|
Configuration 50 [-]
| AND |
|
Configuration 51 [-]
|
Configuration 52 [-]
| AND |
|
Configuration 53 [-]
| AND |
|
Configuration 54 [-]
|
Configuration 55 [-]
| AND |
|
Configuration 56 [-]
| AND |
|
Configuration 57 [-]
|
Configuration 58 [-]
| AND |
|
Configuration 59 [-]
| AND |
|
Configuration 60 [-]
| AND |
|
Configuration 61 [-]
|
Configuration 62 [-]
| AND |
|
Configuration 63 [-]
|
No data.
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54461 | An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected. |
Solution
Upgrade to the product version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-140960
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-140960 |
|
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-09-11T20:38:29.704Z
Reserved: 2023-08-29T15:54:56.119Z
Link: CVE-2023-4608
Updated: 2024-08-02T07:31:06.539Z
Status : Modified
Published: 2023-10-25T18:17:41.670
Modified: 2024-11-21T08:35:32.260
Link: CVE-2023-4608
No data.
OpenCVE Enrichment
No data.
EUVD