Description
An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
References (1)
Core 1
Core References
Vendor Advisory
https://support.lenovo.com/us/en/product_security/LEN-140960
Scores
CVSS v3
4.1
EPSS
0.0009
EPSS Percentile
26.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-89
Status
published
Products (50)
lenovo/thinkagile_hx1331_firmware
lenovo/thinkagile_hx2330_firmware
lenovo/thinkagile_hx2331_firmware
lenovo/thinkagile_hx3330_firmware
lenovo/thinkagile_hx3331_firmware
lenovo/thinkagile_hx3375_firmware
lenovo/thinkagile_hx3376_firmware
lenovo/thinkagile_hx5530_firmware
lenovo/thinkagile_hx5531_firmware
lenovo/thinkagile_hx7530_firmware
... and 40 more
Published
Oct 25, 2023
Tracked Since
Feb 18, 2026