CVE-2023-4606

high-risk
Published 2023-10-25

An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.

Do I need to act?

-
0.12% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.1/10 High
NETWORK / LOW complexity

Affected Products (20)

Thinkagile Hx5530 Firmware
Thinkagile Hx7530 Firmware
Thinkagile Vx3331 Firmware
Thinkagile Hx1331 Firmware
Thinkagile Hx2330 Firmware
Thinkagile Hx2331 Firmware
Thinkagile Hx3330 Firmware
Thinkagile Hx3331 Firmware
Thinkagile Hx3375 Firmware
Thinkagile Hx3376 Firmware
Thinkagile Hx5531 Firmware
Thinkagile Hx7531 Firmware
Thinkagile Mx3330-F All-Flash Firmware
Thinkagile Mx3330-H Hybrid Firmware
Thinkagile Mx3331-F All-Flash Firmware
Thinkagile Mx3331-H Hybrid Firmware
Thinkagile Mx3530 F All Flash Firmware
Thinkagile Mx3530-H Hybrid Firmware
Thinkagile Mx3531 H Hybrid Firmware
Thinkagile Mx3531-F All-Flash Firmware

Affected Vendors

55
/ 100
high-risk
Severity 28/34 · Critical
Exploitability 0/34 · Minimal
Exposure 27/34 · High