LOW · 2.7

CVE-2022-34888

The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls...

Vulnerability Description

The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect.

CVSS Score

2.7

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
LenovoThinkagile Vx3331 Firmware< 1.80_afbt20n
LenovoThinkagile Vx3331-
LenovoThinkagile Hx Enclosure Certified Node Firmware< 5.20_tei3c8m
LenovoThinkagile Hx Enclosure Certified Node-
LenovoThinkagile Hx1021 Firmware< 3.60_tei386m
LenovoThinkagile Hx1021-
LenovoThinkagile Hx1320 Firmware< 8.40-cdi394n
LenovoThinkagile Hx1320-
LenovoThinkagile Hx1321 Firmware< 8.40-cdi394n
LenovoThinkagile Hx1321-
LenovoThinkagile Hx1520-R Firmware< 8.40-cdi394n
LenovoThinkagile Hx1520-R-
LenovoThinkagile Hx1521-R Firmware< 8.40-cdi394n
LenovoThinkagile Hx1521-R-
LenovoThinkagile Hx2320-E Firmware< 8.40-cdi394n
LenovoThinkagile Hx2320-E-
LenovoThinkagile Hx2321 Firmware< 8.40-cdi394n
LenovoThinkagile Hx2321-
LenovoThinkagile Hx2720-E Firmware< 5.20_tei3c8m
LenovoThinkagile Hx2720-E-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-34888?

CVE-2022-34888 is a vulnerability with a CVSS score of 2.7 (LOW). The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls...

How severe is CVE-2022-34888?

CVE-2022-34888 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-34888?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Thinkagile Vx3331 Firmware, Lenovo Thinkagile Vx3331, Lenovo Thinkagile Hx Enclosure Certified Node Firmware, Lenovo Thinkagile Hx Enclosure Certified Node, Lenovo Thinkagile Hx1021 Firmware.