CVE-2023-4608: SQL Injection
Published Oct 24, 2023
·Updated
An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.
This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
Affected Software
104 affected components
All of the following
Lenovo Thinkagile Hx5530 Firmware
Lenovo Thinkagile Hx5530
All of the following
Lenovo Thinkagile Hx7530 Firmware
Lenovo Thinkagile Hx7530
All of the following
Lenovo Thinkagile Vx3331 Firmware
Lenovo Thinkagile Vx3331
All of the following
Lenovo Thinkagile Hx1331 Firmware
Lenovo Thinkagile Hx1331
All of the following
Lenovo Thinkagile Hx2330 Firmware
Lenovo Thinkagile Hx2330
All of the following
Lenovo Thinkagile Hx2331 Firmware
Lenovo Thinkagile Hx2331
All of the following
Lenovo Thinkagile Hx3330 Firmware
Lenovo Thinkagile Hx3330
All of the following
Lenovo Thinkagile Hx3331 Firmware
Lenovo Thinkagile Hx3331
All of the following
Lenovo Thinkagile Hx3375 Firmware
Lenovo Thinkagile Hx3375
All of the following
Lenovo Thinkagile Hx3376 Firmware
Lenovo Thinkagile Hx3376
All of the following
Lenovo Thinkagile Hx5531 Firmware
Lenovo Thinkagile Hx5531
All of the following
Lenovo Thinkagile Hx7531 Firmware
Lenovo Thinkagile Hx7531
All of the following
Lenovo Thinkagile Mx3330-f All-flash Firmware
Lenovo Thinkagile Mx3330-f All-flash
All of the following
Lenovo Thinkagile Mx3330-h Hybrid Firmware
Lenovo Thinkagile Mx3330-h Hybrid
All of the following
Lenovo Thinkagile Mx3331-f All-flash Firmware
Lenovo Thinkagile Mx3331-f All-flash
All of the following
Lenovo Thinkagile Mx3331-h Hybrid Firmware
Lenovo Thinkagile Mx3331-h Hybrid
All of the following
Lenovo Thinkagile Mx3530 F All Flash Firmware
Lenovo Thinkagile Mx3530 F All Flash
All of the following
Lenovo Thinkagile Mx3530-h Hybrid Firmware
Lenovo Thinkagile Mx3530-h Hybrid
All of the following
Lenovo Thinkagile Mx3531 H Hybrid Firmware
Lenovo Thinkagile Mx3531 H Hybrid
All of the following
Lenovo Thinkagile Mx3531-f All-flash Firmware
Lenovo Thinkagile Mx3531-f All-flash
All of the following
Lenovo Thinkagile Vx2330 Firmware
Lenovo Thinkagile Vx2330
All of the following
Lenovo Thinkagile Vx3330 Firmware
Lenovo Thinkagile Vx3330
All of the following
Lenovo Thinkagile Vx3530-g Firmware
Lenovo Thinkagile Vx3530-g
All of the following
Lenovo Thinkagile Vx5530 Firmware
Lenovo Thinkagile Vx5530
All of the following
Lenovo Thinkagile Vx7330 Firmware
Lenovo Thinkagile Vx7330
All of the following
Lenovo Thinkagile Vx7530 Firmware
Lenovo Thinkagile Vx7530
All of the following
Lenovo Thinkagile Vx7531 Firmware
Lenovo Thinkagile Vx7531
All of the following
Lenovo Thinksystem Sd630 V2 Firmware
Lenovo Thinksystem Sd630 V2
All of the following
Lenovo Thinksystem Sd650 V2 Firmware
Lenovo Thinksystem Sd650 V2
Lenovo Thinksystem Sd650 V3 Firmware
All of the following
Lenovo Thinksystem Sd650-n V2 Firmware
Lenovo Thinksystem Sd650-n V2
Lenovo Thinksystem Sd665 V3 Firmware
All of the following
Lenovo Thinksystem Sn550 V2 Firmware
Lenovo Thinksystem Sn550 V2
All of the following
Lenovo Thinksystem Sr250 Firmware
Lenovo Thinksystem Sr250 V2
All of the following
Lenovo Thinksystem Sr258 V2 Firmware
Lenovo Thinksystem Sr258 V2
All of the following
Lenovo Thinksystem Sr630 V2 Firmware
Lenovo Thinksystem Sr630 V2
Lenovo Thinksystem Sr630 V3 Firmware
Lenovo Thinksystem Sr635 V3 Firmware
All of the following
Lenovo Thinksystem Sr645 Firmware
Lenovo Thinksystem Sr645
All of the following
Lenovo Thinksystem Sr645 V3 Firmware
Lenovo Thinksystem Sr645 V3
All of the following
Lenovo Thinksystem Sr650 V2 Firmware
Lenovo Thinksystem Sr650 V2
Lenovo Thinksystem Sr650 V3 Firmware
Lenovo Thinksystem Sr655 V3 Firmware
All of the following
Lenovo Thinksystem Sr665 Firmware
Lenovo Thinksystem Sr665
Lenovo Thinksystem Sr665 V3 Firmware
All of the following
Lenovo Thinksystem Sr670 Firmware
Lenovo Thinksystem Sr670
All of the following
Lenovo Thinksystem Sr670 V2 Firmware
Lenovo Thinksystem Sr670 V2
Lenovo Thinksystem Sr675 V3 Firmware
All of the following
Lenovo Thinksystem Sr850 V2 Firmware
Lenovo Thinksystem Sr850 V2
Lenovo Thinksystem Sr850 V3 Firmware
All of the following
Lenovo Thinksystem Sr860 V2 Firmware
Lenovo Thinksystem Sr860 V2
Lenovo Thinksystem Sr860 V3 Firmware
All of the following
Lenovo Thinksystem St250 V2 Firmware
Lenovo Thinksystem St250 V2
All of the following
Lenovo Thinksystem St258 V2 Firmware
Lenovo Thinksystem St258 V2
All of the following
Lenovo Thinksystem St650 V2 Firmware
Lenovo Thinksystem St650 V2
Lenovo Thinksystem St650 V3 Firmware
All of the following
Lenovo Thinksystem St658 V2 Firmware
Lenovo Thinksystem St658 V2
Lenovo Thinksystem St658 V3 Firmware
Remediation
Information
Upgrade to the product version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-140960
Event History
Oct 24, 2023
CVE Published
via MITRE·08:25 PM
Data Sourced
via MITRE·08:25 PM
RemedyDescriptionSeverityWeakness
Oct 25, 2023
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-4608?
CVE-2023-4608 has a severity rating that indicates a significant risk for authenticated users with elevated privileges.
2
How do I fix CVE-2023-4608?
To fix CVE-2023-4608, you should update the affected ThinkSystem and ThinkAgile firmware to the latest version provided by Lenovo.
3
Which systems are affected by CVE-2023-4608?
CVE-2023-4608 affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
4
What type of vulnerability is CVE-2023-4608?
CVE-2023-4608 is an authenticated blind SQL injection vulnerability.
5
Who is impacted by CVE-2023-4608?
Authenticated users with elevated privileges on affected Lenovo servers could exploit CVE-2023-4608.