MEDIUM🇵🇱 Wersja polska

CVE-2024-45104

CVSS 6.3v3.1pub. 2024-09-13upd. 2024-12-13

A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
  • Lenovo Xclarity Administrator

    APP
    Lenovo
    < 4.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2017-17833CRITICAL9.8PL ✓same product

OpenSLP — uszkodzenie pamięci sterty umożliwiające RCE lub DoS

CVE-2016-8233CRITICAL9.8PL ✓same product

Lenovo XClarity Administrator — dane uwierzytelniające w logach w postaci jawnej

CVE-2023-34418HIGH8.1same product

A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LX...

CVE-2023-3113HIGH8.2same product

An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model...

CVE-2023-34420HIGH7.2same product

A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through cr...