Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
Unknown

CVE-2024-45102

Disclosure Date: January 14, 2025 (last updated January 15, 2025)
A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their permissions for a connected XCC instance when using LXCA as a Single Sign On (SSO) provider for XCC instances.
Attacker Value
Unknown

CVE-2024-45104

Disclosure Date: September 13, 2024 (last updated September 19, 2024)
A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.
Attacker Value
Unknown

CVE-2024-45103

Disclosure Date: September 13, 2024 (last updated September 19, 2024)
A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.
Attacker Value
Unknown

CVE-2024-45101

Disclosure Date: September 13, 2024 (last updated January 05, 2025)
A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, authenticated LXCA user’s XCC session if they can convince the user to click on a specially crafted URL.
0
Attacker Value
Unknown

CVE-2023-4605

Disclosure Date: April 05, 2024 (last updated January 05, 2025)
A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.
0
Attacker Value
Unknown

CVE-2023-3113

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files.
Attacker Value
Unknown

CVE-2023-34422

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation.
Attacker Value
Unknown

CVE-2023-34421

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation.
Attacker Value
Unknown

CVE-2023-34420

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API.
Attacker Value
Unknown

CVE-2023-34418

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API.