PT-2024-31433 · Lenovo · Lenovo Xclarity Administrator

Published

2024-09-13

·

Updated

2024-12-13

·

CVE-2024-45103

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Lenovo XClarity Administrator versions up to 4.0
Description A valid, authenticated LXCA user may be able to unmanage an LXCA managed device through the LXCA web interface without sufficient privileges. This issue may lead to potential privilege escalation.
Recommendations For versions up to 4.0, upgrade the affected component immediately to resolve the issue. As a temporary workaround, consider restricting access to the LXCA web interface to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-45103

Affected Products

Lenovo Xclarity Administrator