
CVE-2024-45105
https://notcve.org/view.php?id=CVE-2024-45105
13 Sep 2024 — An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with elevated privileges to execute arbitrary code. • https://support.lenovo.com/us/en/product_security/LEN-165524 • CWE-825: Expired Pointer Dereference •

CVE-2023-4608
https://notcve.org/view.php?id=CVE-2023-4608
24 Oct 2023 — An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected. Un usuario de XCC autenticado con privilegios elevados puede realizar una inyección blind SQL en casos limitados a través de un comando API manipulado. Esto afecta a los servidores ThinkSystem v2 y v3 con XCC; Los servidores ThinkSystem v1 no se ven afectados. • https://support.lenovo.com/us/en/product_security/LEN-140960 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-4607
https://notcve.org/view.php?id=CVE-2023-4607
24 Oct 2023 — An authenticated XCC user can change permissions for any user through a crafted API command. Un usuario XCC autenticado puede cambiar los permisos de cualquier usuario mediante un comando API manipulado. • https://support.lenovo.com/us/en/product_security/LEN-140960 • CWE-269: Improper Privilege Management •

CVE-2023-4606
https://notcve.org/view.php?id=CVE-2023-4606
24 Oct 2023 — An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected. Un usuario XCC autenticado con permiso de solo lectura puede cambiar la contraseña de un usuario diferente mediante un comando API manipulado. Esto afecta a los servidores ThinkSystem v2 y v3 con XCC; Los servidores ThinkSystem v1 no se ven afectados. • https://support.lenovo.com/us/en/product_security/LEN-140960 • CWE-862: Missing Authorization •