Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown
CVE-2024-8281
Disclosure Date: September 13, 2024 (last updated January 05, 2025)
An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection through specially crafted command line input in the XCC SSH captive shell.
0
Attacker Value
Unknown
CVE-2024-8280
Disclosure Date: September 13, 2024 (last updated January 05, 2025)
An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection or cause a recoverable denial of service using a specially crafted file.
0
Attacker Value
Unknown
CVE-2024-8279
Disclosure Date: September 13, 2024 (last updated January 05, 2025)
A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.
0
Attacker Value
Unknown
CVE-2024-8278
Disclosure Date: September 13, 2024 (last updated January 05, 2025)
A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands.
0
Attacker Value
Unknown
CVE-2024-8059
Disclosure Date: September 13, 2024 (last updated September 14, 2024)
IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.
0
Attacker Value
Unknown
CVE-2024-45105
Disclosure Date: September 13, 2024 (last updated January 05, 2025)
An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with elevated privileges to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2024-8105
Disclosure Date: August 26, 2024 (last updated August 27, 2024)
A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.
0
Attacker Value
Unknown
CVE-2023-4607
Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user can change permissions for any user through a crafted API command.
0
Attacker Value
Unknown
CVE-2023-25492
Disclosure Date: May 01, 2023 (last updated October 08, 2023)
A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format string injection vulnerability in a web interface API.
0
Attacker Value
Unknown
CVE-2023-0683
Disclosure Date: May 01, 2023 (last updated October 08, 2023)
A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call.
0