CVE-2023-29058

CVSS V2 None CVSS V3 None
Description
A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions.
Overview
  • CVE ID
  • CVE-2023-29058
  • Assigner
  • psirt@lenovo.com
  • Vulnerability Status
  • Received
  • Published Version
  • 2023-04-28T21:15:08
  • Last Modified Date
  • 2023-04-28T21:15:08
References
History
Created Old Value New Value Data Type Notes
2023-04-28 22:00:48 Added to TrackCVE
2023-04-28 22:00:49 Weakness Enumeration new