CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

lenovo

thinksystem_st650_v3_firmware

3 known vulnerabilities · sorted by CVSS score

CVE-2023-4606
HIGH8.1

An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.

lenovo / thinkagile_hx5530_firmware+62
Network
Published Oct 25, 2023
CVE-2023-4607
HIGH7.5

An authenticated XCC user can change permissions for any user through a crafted API command.

lenovo / thinkagile_hx5530_firmware+135
Network
Published Oct 25, 2023
CVE-2023-4608
MEDIUM4.1

An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.  This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.

lenovo / thinkagile_hx5530_firmware+62
Network
Published Oct 25, 2023