CVE-2023-29058
CVSS V2 None
CVSS V3 None
Description
A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions.
Overview
- CVE ID
- CVE-2023-29058
- Assigner
- psirt@lenovo.com
- Vulnerability Status
- Received
- Published Version
- 2023-04-28T21:15:08
- Last Modified Date
- 2023-04-28T21:15:08
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://support.lenovo.com/us/en/product_security/LEN-118321 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-29058 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29058 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-04-28 22:00:48 | Added to TrackCVE | |||
2023-04-28 22:00:49 | Weakness Enumeration | new |