← Back

Thinkagile Mx3330 F All Flash Firmware

thinkagile_mx3330-f_all-flash_firmware

Vendor: Lenovo • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lenovo
58Thinkagile Hx1331 Firmware
Thinkagile Hx2330 FirmwareThinkagile Hx2331 Firmware+55 more
Jun 17, 2026
Oct 25, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.  This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not aff...Show more
An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.  This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.Show less
1Lenovo
123Thinkagile Hx1021 Edg Firmware
Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+120 more
Jun 17, 2026
Oct 25, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An authenticated XCC user can change permissions for any user through a crafted API command.
1Lenovo
58Thinkagile Hx1331 Firmware
Thinkagile Hx2330 FirmwareThinkagile Hx2331 Firmware+55 more
Jun 17, 2026
Oct 25, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
1Lenovo
287Ideacentre 3 07ada05 Firmware
Ideacentre 3 07imb05 FirmwareIdeacentre 3 07iab7 Firmware+284 more
Jun 17, 2026
Jan 30, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.