Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-4606


An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.


Security Impact Summary

This vulnerability carries a HIGH severity rating with a CVSS v3.1 score of 8.1, indicating it can be exploited remotely over the network with relatively low complexity without requiring user interaction requiring only low-level privileges . The vulnerability impacts integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 104 products from lenovo, from lenovo, from lenovo and 101 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2023, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2023-10-25T18:17:41.487

Last Modified

2024-11-21T08:35:31.833

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-862
  • Type: Primary
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System lenovo thinkagile_hx5530_firmware - Yes
Hardware lenovo thinkagile_hx5530 - No
Operating System lenovo thinkagile_hx7530_firmware - Yes
Hardware lenovo thinkagile_hx7530 - No
Operating System lenovo thinkagile_vx3331_firmware - Yes
Hardware lenovo thinkagile_vx3331 - No
Operating System lenovo thinkagile_hx1331_firmware - Yes
Hardware lenovo thinkagile_hx1331 - No
Operating System lenovo thinkagile_hx2330_firmware - Yes
Hardware lenovo thinkagile_hx2330 - No
Operating System lenovo thinkagile_hx2331_firmware - Yes
Hardware lenovo thinkagile_hx2331 - No
Operating System lenovo thinkagile_hx3330_firmware - Yes
Hardware lenovo thinkagile_hx3330 - No
Operating System lenovo thinkagile_hx3331_firmware - Yes
Hardware lenovo thinkagile_hx3331 - No
Operating System lenovo thinkagile_hx3331_firmware - Yes
Hardware lenovo thinkagile_hx3331 - No
Operating System lenovo thinkagile_hx3375_firmware - Yes
Hardware lenovo thinkagile_hx3375 - No
Operating System lenovo thinkagile_hx3376_firmware - Yes
Hardware lenovo thinkagile_hx3376 - No
Operating System lenovo thinkagile_hx5531_firmware - Yes
Hardware lenovo thinkagile_hx5531 - No
Operating System lenovo thinkagile_hx7530_firmware - Yes
Hardware lenovo thinkagile_hx7530 - No
Operating System lenovo thinkagile_hx7531_firmware - Yes
Hardware lenovo thinkagile_hx7531 - No
Operating System lenovo thinkagile_hx7531_firmware - Yes
Hardware lenovo thinkagile_hx7531 - No
Operating System lenovo thinkagile_mx3330-f_all-flash_firmware - Yes
Hardware lenovo thinkagile_mx3330-f_all-flash - No
Operating System lenovo thinkagile_mx3330-h_hybrid_firmware - Yes
Hardware lenovo thinkagile_mx3330-h_hybrid - No
Operating System lenovo thinkagile_mx3331-f_all-flash_firmware - Yes
Hardware lenovo thinkagile_mx3331-f_all-flash - No
Operating System lenovo thinkagile_mx3331-h_hybrid_firmware - Yes
Hardware lenovo thinkagile_mx3331-h_hybrid - No
Operating System lenovo thinkagile_mx3530_f_all_flash_firmware - Yes
Hardware lenovo thinkagile_mx3530_f_all_flash - No
Operating System lenovo thinkagile_mx3530-h_hybrid_firmware - Yes
Hardware lenovo thinkagile_mx3530-h_hybrid - No
Operating System lenovo thinkagile_mx3531_h_hybrid_firmware - Yes
Hardware lenovo thinkagile_mx3531_h_hybrid - No
Operating System lenovo thinkagile_mx3531-f_all-flash_firmware - Yes
Hardware lenovo thinkagile_mx3531-f_all-flash - No
Operating System lenovo thinkagile_vx2330_firmware - Yes
Hardware lenovo thinkagile_vx2330 - No
Operating System lenovo thinkagile_vx3330_firmware - Yes
Hardware lenovo thinkagile_vx3330 - No
Operating System lenovo thinkagile_vx3530-g_firmware - Yes
Hardware lenovo thinkagile_vx3530-g - No
Operating System lenovo thinkagile_vx5530_firmware - Yes
Hardware lenovo thinkagile_vx5530 - No
Operating System lenovo thinkagile_vx7330_firmware - Yes
Hardware lenovo thinkagile_vx7330 - No
Operating System lenovo thinkagile_vx7530_firmware - Yes
Hardware lenovo thinkagile_vx7530 - No
Operating System lenovo thinkagile_vx7531_firmware - Yes
Hardware lenovo thinkagile_vx7531 - No
Operating System lenovo thinksystem_sd630_v2_firmware - Yes
Hardware lenovo thinksystem_sd630_v2 - No
Operating System lenovo thinksystem_sd650_v2_firmware - Yes
Hardware lenovo thinksystem_sd650_v2 - No
Operating System lenovo thinksystem_sd650_v3_firmware - Yes
Operating System lenovo thinksystem_sd650-n_v2_firmware - Yes
Hardware lenovo thinksystem_sd650-n_v2 - No
Operating System lenovo thinksystem_sd665_v3_firmware - Yes
Operating System lenovo thinksystem_sn550_v2_firmware - Yes
Hardware lenovo thinksystem_sn550_v2 - No
Operating System lenovo thinksystem_sr250_firmware - Yes
Hardware lenovo thinksystem_sr250_v2 - No
Operating System lenovo thinksystem_sr258_v2_firmware - Yes
Hardware lenovo thinksystem_sr258_v2 - No
Operating System lenovo thinksystem_sr630_v2_firmware - Yes
Hardware lenovo thinksystem_sr630_v2 - No
Operating System lenovo thinksystem_sr630_v3_firmware - Yes
Operating System lenovo thinksystem_sr635_v3_firmware - Yes
Operating System lenovo thinksystem_sr645_firmware - Yes
Hardware lenovo thinksystem_sr645 - No
Operating System lenovo thinksystem_sr645_v3_firmware - Yes
Hardware lenovo thinksystem_sr645_v3 - No
Operating System lenovo thinksystem_sr650_v2_firmware - Yes
Hardware lenovo thinksystem_sr650_v2 - No
Operating System lenovo thinksystem_sr650_v3_firmware - Yes
Operating System lenovo thinksystem_sr655_v3_firmware - Yes
Operating System lenovo thinksystem_sr665_firmware - Yes
Hardware lenovo thinksystem_sr665 - No
Operating System lenovo thinksystem_sr665_v3_firmware - Yes
Operating System lenovo thinksystem_sr670_firmware - Yes
Hardware lenovo thinksystem_sr670 - No
Operating System lenovo thinksystem_sr670_v2_firmware - Yes
Hardware lenovo thinksystem_sr670_v2 - No
Operating System lenovo thinksystem_sr675_v3_firmware - Yes
Operating System lenovo thinksystem_sr850_v2_firmware - Yes
Hardware lenovo thinksystem_sr850_v2 - No
Operating System lenovo thinksystem_sr850_v2_firmware - Yes
Hardware lenovo thinksystem_sr850_v2 - No
Operating System lenovo thinksystem_sr850_v3_firmware - Yes
Operating System lenovo thinksystem_sr860_v2_firmware - Yes
Hardware lenovo thinksystem_sr860_v2 - No
Operating System lenovo thinksystem_sr860_v2_firmware - Yes
Hardware lenovo thinksystem_sr860_v2 - No
Operating System lenovo thinksystem_sr860_v3_firmware - Yes
Operating System lenovo thinksystem_st250_v2_firmware - Yes
Hardware lenovo thinksystem_st250_v2 - No
Operating System lenovo thinksystem_st258_v2_firmware - Yes
Hardware lenovo thinksystem_st258_v2 - No
Operating System lenovo thinksystem_st650_v2_firmware - Yes
Hardware lenovo thinksystem_st650_v2 - No
Operating System lenovo thinksystem_st650_v3_firmware - Yes
Operating System lenovo thinksystem_st658_v2_firmware - Yes
Hardware lenovo thinksystem_st658_v2 - No
Operating System lenovo thinksystem_st658_v3_firmware - Yes

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For lenovo's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.