CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Lenovo 58Thinkagile Hx1331 Firmware Thinkagile Hx2330 FirmwareThinkagile Hx2331 Firmware+55 moreJun 17, 2026 Oct 25, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not aff...Show more |
1Lenovo 123Thinkagile Hx1021 Edg Firmware Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+120 moreJun 17, 2026 Oct 25, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 An authenticated XCC user can change permissions for any user through a crafted API command. |
1Lenovo 58Thinkagile Hx1331 Firmware Thinkagile Hx2330 FirmwareThinkagile Hx2331 Firmware+55 moreJun 17, 2026 Oct 25, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.
This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected. |