« Volver al listado

Lenovo

Lenovo Thinkagile Mx3531 H Hybrid Firmware: vulnerabilidades y CVE

Lenovo Thinkagile Mx3531 H Hybrid Firmware tiene 4 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE4
Últimos 12 meses0
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-4608Alta (7.2)0.40%—25 oct 2023
An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not…
CVE-2023-4607Alta (8.8)0.52%—25 oct 2023
An authenticated XCC user can change permissions for any user through a crafted API command.
CVE-2023-4606Alta (8.1)0.55%—25 oct 2023
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
CVE-2022-40137Media (6.7)0.23%—30 ene 2023
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.

Otros productos de Lenovo