Vulnerability Description
A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Thinkagile Hx5530 Firmware | < 2.93_afbt30p |
| Lenovo | Thinkagile Hx5530 | - |
| Lenovo | Thinkagile Hx7530 Firmware | < 2.93_afbt30p |
| Lenovo | Thinkagile Hx7530 | - |
| Lenovo | Thinkagile Vx3331 Firmware | < 2.93_afbt30p |
| Lenovo | Thinkagile Vx3331 | - |
| Lenovo | Thinkagile Hx Enclosure Firmware | < 3.72_tei388s |
| Lenovo | Thinkagile Hx Enclosure | - |
| Lenovo | Thinkagile Hx1021 Firmware | < 3.72_tei388s |
| Lenovo | Thinkagile Hx1021 | - |
| Lenovo | Thinkagile Hx1320 Firmware | < 8.88_cdi3a4a |
| Lenovo | Thinkagile Hx1320 | - |
| Lenovo | Thinkagile Hx1321 Firmware | < 8.88_cdi3a4a |
| Lenovo | Thinkagile Hx1321 | - |
| Lenovo | Thinkagile Hx1331 Firmware | < 2.93_afbt30p |
| Lenovo | Thinkagile Hx1331 | - |
| Lenovo | Thinkagile Hx1520-R Firmware | < 8.88_cdi3a4a |
| Lenovo | Thinkagile Hx1520-R | - |
| Lenovo | Thinkagile Hx1521-R Firmware | < 8.88_cdi3a4a |
| Lenovo | Thinkagile Hx1521-R | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/LEN-118321Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-118321Vendor Advisory
FAQ
What is CVE-2023-29056?
CVE-2023-29056 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Auth...
How severe is CVE-2023-29056?
CVE-2023-29056 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-29056?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Thinkagile Hx5530 Firmware, Lenovo Thinkagile Hx5530, Lenovo Thinkagile Hx7530 Firmware, Lenovo Thinkagile Hx7530, Lenovo Thinkagile Vx3331 Firmware.