CVE Vulnerabilities

CVE-2023-29058

Published: Apr 28, 2023 | Modified: May 08, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions.

Affected Software

Name Vendor Start Version End Version
Thinkagile_hx5530_firmware Lenovo * 2.93_afbt30p (excluding)

References