CVE-2023-4607: High severity lenovo thinkagile hx5530 firmware vulnerability
An authenticated XCC user can change permissions for any user through a crafted API command.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4607?
CVE-2023-4607 is classified as a critical vulnerability due to its exploitation leading to unauthorized permission changes.
Who is affected by CVE-2023-4607?
CVE-2023-4607 affects authenticated users of Lenovo's ThinkAgile product line, particularly those with access to the XCC management console.
How do I fix CVE-2023-4607?
To mitigate CVE-2023-4607, update to the latest firmware version available from Lenovo that addresses this vulnerability.
What type of vulnerability is CVE-2023-4607?
CVE-2023-4607 is identified as an authenticated access control vulnerability that allows users to alter permissions unlawfully.
What can attackers do with CVE-2023-4607?
An attacker exploiting CVE-2023-4607 can gain the ability to change user permissions within the system, potentially leading to further security breaches.