Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-29058: Lenovo XClarity Controller (XCC) Vulnerabilities - Lenovo Support US

A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions.

CVE
#vulnerability#lenovo#auth#ssh

About Lenovo

  • Our Company
  • News
  • Investor Relations
  • Sustainability
  • Product Compliance
  • Product Security
  • Lenovo Open Source
  • Legal Information
  • Jobs at Lenovo

Shop

  • Laptops & Ultrabooks
  • Tablets
  • Desktops & All-in-Ones
  • Workstations
  • Accessories & Software
  • Servers
  • Storage
  • Networking
  • Laptop Deals
  • Outlet

Support

  • Drivers & Software
  • How To’s
  • Warranty Lookup
  • Parts Lookup
  • Contact Us
  • Repair Status Check
  • Imaging & Security Resources

Resources

  • Where to Buy
  • Shopping Help
  • Track Order Status
  • Product Specifications (PSREF)
  • Forums
  • Registration
  • Product Accessibility
  • Environmental Information
  • Gaming Community
  • LenovoEDU Community
  • LenovoPRO Community

© Lenovo.
| | | |

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907