Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2023-4608

Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.  This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
Attacker Value
Unknown

CVE-2023-4607

Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user can change permissions for any user through a crafted API command.
Attacker Value
Unknown

CVE-2023-4606

Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
Attacker Value
Unknown

CVE-2022-40137

Disclosure Date: January 30, 2023 (last updated October 08, 2023)
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2022-40134

Disclosure Date: January 30, 2023 (last updated October 08, 2023)
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.