An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
| Vendor | Product | Versions | Fixed In |
|---|---|---|---|
| lenovo | thinkagile_hx5530_firmware | - | - |
| lenovo | thinkagile_hx7530_firmware | - | - |
| lenovo | thinkagile_vx3331_firmware |
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
63
Affected Products
2
References
lenovo / thinkagile_hx5530_firmware
| - |
| - |
| lenovo | thinkagile_hx1331_firmware | - | - |
| lenovo | thinkagile_hx2330_firmware | - | - |
| lenovo | thinkagile_hx2331_firmware | - | - |
| lenovo | thinkagile_hx3330_firmware | - | - |
| lenovo | thinkagile_hx3331_firmware | - | - |
| lenovo | thinkagile_hx3331_firmware | - | - |
| lenovo | thinkagile_hx3375_firmware | - | - |
| lenovo | thinkagile_hx3376_firmware | - | - |
| lenovo | thinkagile_hx5531_firmware | - | - |
| lenovo | thinkagile_hx7530_firmware | - | - |
| lenovo | thinkagile_hx7531_firmware | - | - |
| lenovo | thinkagile_hx7531_firmware | - | - |
| lenovo | thinkagile_mx3330-f_all-flash_firmware | - | - |
| lenovo | thinkagile_mx3330-h_hybrid_firmware | - | - |
| lenovo | thinkagile_mx3331-f_all-flash_firmware | - | - |
| lenovo | thinkagile_mx3331-h_hybrid_firmware | - | - |
| lenovo | thinkagile_mx3530_f_all_flash_firmware | - | - |
| lenovo | thinkagile_mx3530-h_hybrid_firmware | - | - |
| lenovo | thinkagile_mx3531_h_hybrid_firmware | - | - |
| lenovo | thinkagile_mx3531-f_all-flash_firmware | - | - |
| lenovo | thinkagile_vx2330_firmware | - | - |
| lenovo | thinkagile_vx3330_firmware | - | - |
| lenovo | thinkagile_vx3530-g_firmware | - | - |
| lenovo | thinkagile_vx5530_firmware | - | - |
| lenovo | thinkagile_vx7330_firmware | - | - |
| lenovo | thinkagile_vx7530_firmware | - | - |
| lenovo | thinkagile_vx7531_firmware | - | - |
| lenovo | thinksystem_sd630_v2_firmware | - | - |
| lenovo | thinksystem_sd650_v2_firmware | - | - |
| lenovo | thinksystem_sd650_v3_firmware | - | - |
| lenovo | thinksystem_sd650-n_v2_firmware | - | - |
| lenovo | thinksystem_sd665_v3_firmware | - | - |
| lenovo | thinksystem_sn550_v2_firmware | - | - |
| lenovo | thinksystem_sr250_firmware | - | - |
| lenovo | thinksystem_sr258_v2_firmware | - | - |
| lenovo | thinksystem_sr630_v2_firmware | - | - |
| lenovo | thinksystem_sr630_v3_firmware | - | - |
| lenovo | thinksystem_sr635_v3_firmware | - | - |
| lenovo | thinksystem_sr645_firmware | - | - |
| lenovo | thinksystem_sr645_v3_firmware | - | - |
| lenovo | thinksystem_sr650_v2_firmware | - | - |
| lenovo | thinksystem_sr650_v3_firmware | - | - |
| lenovo | thinksystem_sr655_v3_firmware | - | - |
| lenovo | thinksystem_sr665_firmware | - | - |
| lenovo | thinksystem_sr665_v3_firmware | - | - |
| lenovo | thinksystem_sr670_firmware | - | - |
| lenovo | thinksystem_sr670_v2_firmware | - | - |
| lenovo | thinksystem_sr675_v3_firmware | - | - |
| lenovo | thinksystem_sr850_v2_firmware | - | - |
| lenovo | thinksystem_sr850_v2_firmware | - | - |
| lenovo | thinksystem_sr850_v3_firmware | - | - |
| lenovo | thinksystem_sr860_v2_firmware | - | - |
| lenovo | thinksystem_sr860_v2_firmware | - | - |
| lenovo | thinksystem_sr860_v3_firmware | - | - |
| lenovo | thinksystem_st250_v2_firmware | - | - |
| lenovo | thinksystem_st258_v2_firmware | - | - |
| lenovo | thinksystem_st650_v2_firmware | - | - |
| lenovo | thinksystem_st650_v3_firmware | - | - |
| lenovo | thinksystem_st658_v2_firmware | - | - |
| lenovo | thinksystem_st658_v3_firmware | - | - |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Exploitability
Impact