PT-2024-10056 · Lenovo · Lenovo Xclarity Controller

Published

2024-07-09

·

Updated

2024-07-29

·

CVE-2024-38511

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Lenovo XClarity Controller (XCC) for Lenovo ThinkSystem servers (affected versions not specified)
Description The issue is related to a lack of neutralization of special elements, which could allow a remote attacker to execute arbitrary commands using specially crafted files. It is a privilege escalation vulnerability discovered in the upload processing functionality of XCC, allowing an authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-00194
CVE-2024-38511

Affected Products

Lenovo Xclarity Controller