GPU VulnDB

Database/Firmware, BMC & network fabric

Lenovo XClarity Administrator (LXCA, insufficient authorization): An authenticated LXCA user without sufficient

CVE-2024-45104Firmware, BMC & network fabriccurated

Impact

An authenticated LXCA user without sufficient privileges modifies a managed device through a crafted web API call using the device identifier - a horizontal privilege bypass over the fleet management API.

Who can reach it

Authenticated low-privilege LXCA user.

What to do

Apply the LXCA update per LEN-154748. Appliance upgrade; review LXCA role assignments while you are in there.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.