CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Lenovo 68Nextscale N1200 Enclosure Firmware Thinkagile 2u4n FirmwareThinkagile Cp Cb 10 Firmware+65 moreJun 17, 2026 Apr 15, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2
A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function.
|
1Lenovo 123Thinkagile Hx1021 Edg Firmware Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+120 moreJun 17, 2026 Oct 25, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 An authenticated XCC user can change permissions for any user through a crafted API command. |
1Lenovo 109Thinkagile Hx1021 Firmware Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+106 moreJun 17, 2026 May 1, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format string injection vulnerability in a web interface API. |
1Lenovo 109Thinkagile Hx1021 Firmware Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+106 moreJun 17, 2026 May 1, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call. |
1Lenovo 109Thinkagile Hx1021 Firmware Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+106 moreJun 17, 2026 Apr 28, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have t...Show more |
1Lenovo 109Thinkagile Hx1021 Firmware Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+106 moreJun 17, 2026 Apr 28, 2023 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposu...Show more |
1Lenovo 109Thinkagile Hx1021 Firmware Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+106 moreJun 17, 2026 Apr 28, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no...Show more |
1Lenovo 109Thinkagile Hx1021 Firmware Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+106 moreJun 17, 2026 Apr 28, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentica...Show more |