PT-2024-10054 · Lenovo · Lenovo Xclarity Controller

Published

2024-07-09

·

Updated

2024-07-29

·

CVE-2024-38508

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Lenovo XClarity Controller (XCC) (affected versions not specified)
Description A privilege escalation issue was found in the web interface or SSH captive command shell interface of XCC. This could allow an authenticated XCC user with elevated privileges to perform command injection via a specially crafted request. The issue is related to the failure to neutralize special elements, which could enable a remote attacker to execute arbitrary commands.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-00192
CVE-2024-38508

Affected Products

Lenovo Xclarity Controller