CVE-2023-4606
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API comma
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC.
ThinkSystem v1 servers are not affected.
HIGH · CVSS 8.1
EPSS 0.00117
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0