Show filters
331 Total Results
Displaying 1-10 of 331
Sort by:
Attacker Value
Unknown

CVE-2024-8281

Disclosure Date: September 13, 2024 (last updated January 05, 2025)
An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection through specially crafted command line input in the XCC SSH captive shell.
0
Attacker Value
Unknown

CVE-2024-8280

Disclosure Date: September 13, 2024 (last updated January 05, 2025)
An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection or cause a recoverable denial of service using a specially crafted file.
0
Attacker Value
Unknown

CVE-2024-8279

Disclosure Date: September 13, 2024 (last updated January 05, 2025)
A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.
0
Attacker Value
Unknown

CVE-2024-8278

Disclosure Date: September 13, 2024 (last updated January 05, 2025)
A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands.
0
Attacker Value
Unknown

CVE-2024-8059

Disclosure Date: September 13, 2024 (last updated September 14, 2024)
IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.
Attacker Value
Unknown

CVE-2024-45105

Disclosure Date: September 13, 2024 (last updated January 05, 2025)
An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with elevated privileges to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2023-4608

Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.  This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
Attacker Value
Unknown

CVE-2023-4607

Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user can change permissions for any user through a crafted API command.
Attacker Value
Unknown

CVE-2023-4606

Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
Attacker Value
Unknown

CVE-2023-28538

Disclosure Date: September 05, 2023 (last updated October 08, 2023)
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.