Database/Firmware, BMC & network fabric
Lenovo XClarity Controller (XCC) - permission API: An authenticated XCC user can change the permissions of any user
Impact
An authenticated XCC user can change the permissions of any user through a crafted API command - including their own. Fixed in the same advisory as the password-change flaw and with the same practical result: whatever limited BMC account you issued becomes an administrative one, and the attacker inherits out-of-band power control, Virtual Media boot, console access and firmware update rights on the node. The privilege model in this XCC generation should be treated as advisory rather than enforcing until patched.
Who can reach it
Any authenticated XCC account, at any privilege level, reaching the XCC over the out-of-band management VLAN.
What to do
Flash XCC to the per-model version in LEN-140960 - out-of-band, per-node, no host reboot, no job drain. Because the fix is per-SKU, treat it as one campaign covering both this and CVE-2023-4606. Until patched, the only real control is reducing the number of XCC accounts that exist at all, since privilege tiers are not a boundary here.
References
Related entries
- HPE iLO 5 / iLO 6 (authentication bypass): Authentication bypass on the iLO itself, remotely, with no credentialsCVE-2023-50272 · HPE iLO 5 / iLO 6 (authentication bypass)High
- Linux kernel (drivers/infiniband/sw/siw): When soft-iWARP fails to process an inbound MPA connection requestCVE-2023-52513 · Linux kernel (drivers/infiniband/sw/siw)High
- Phoenix SecureCore (TPM configuration / SetupUtility, unsafe UEFI variable handling in SMM): A buffer overflow in howCVE-2024-0762 · Phoenix SecureCore (TPM configuration / SetupUtility, unsafe UEFI variable handling in SMM)High
- Brocade Fabric OS (firmware download credential capture): Fabric OS captures the SFTP/FTP server password usedCVE-2024-10403 · Brocade Fabric OS (firmware download credential capture)High
- Juniper Junos OS Packet Forwarding Engine (VXLAN + ICMP): A high rate of specific ICMP traffic to a device with VXLANCVE-2024-21595 · Juniper Junos OS Packet Forwarding Engine (VXLAN + ICMP)High
- IBM OpenBMC bmcweb HTTPS server (FW1050.00 - FW1050.10): Certain URIs on IBM's OpenBMC-derived bmcweb returnCVE-2024-31916 · IBM OpenBMC bmcweb HTTPS server (FW1050.00 - FW1050.10)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.