HIGH🇵🇱 Wersja polska

CVE-2023-3113

CVSS 8.2v3.1pub. 2023-06-26upd. 2024-11-21

An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
  • Lenovo Xclarity Administrator

    APP
    Lenovo
    < 4.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XXE
CWE
References

Related vulnerabilities

CVE-2017-17833CRITICAL9.8PL ✓same product

OpenSLP — uszkodzenie pamięci sterty umożliwiające RCE lub DoS

CVE-2016-8233CRITICAL9.8PL ✓same product

Lenovo XClarity Administrator — dane uwierzytelniające w logach w postaci jawnej

CVE-2023-34420HIGH7.2same product

A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through cr...

CVE-2023-34418HIGH8.1same product

A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LX...

CVE-2019-19756HIGH7.9same product

An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, ...