Database/Firmware, BMC & network fabric
Lenovo XClarity Administrator (LXCA, insufficient authorization): An authenticated LXCA user without sufficient
CVSS 6.3CVE-2024-45104Firmware, BMC & network fabriccurated
Impact
An authenticated LXCA user without sufficient privileges modifies a managed device through a crafted web API call using the device identifier - a horizontal privilege bypass over the fleet management API.
Who can reach it
Authenticated low-privilege LXCA user.
What to do
Apply the LXCA update per LEN-154748. Appliance upgrade; review LXCA role assignments while you are in there.
References
Related entries
- Keylime verifier: hardcoded TPM quote nonce lets a compromised node replay stockpiled attestationsCVE-2026-6420 · Keylime verifier (TPM quote nonce, push attestation model)Medium
- Arista EOS: ingress ACLs on shared SVIs stop enforcing after a secondary switch card eventCVE-2026-73451 · Arista EOS ingress security ACLs on shared-mode SVIs (dual switch card systems)Medium
- Linux KVM - PV TLB shootdown leaks memory between guest processes: In a KVM guest with paravirtualised TLB enabled, oneCVE-2019-3016 · Linux KVM - PV TLB shootdown leaks memory between guest processesMedium
- APC Network Management Card 2 (AP9630/AP9631/AP9635) in Smart-UPS, Symmetra and Galaxy 3500: Stored/reflectedCVE-2021-22810 · APC Network Management Card 2 (AP9630/AP9631/AP9635) in Smart-UPS, Symmetra and Galaxy 3500Medium
- Arista EOS (TerminAttr / OpenConfig telemetry transport): The streaming-telemetry agent can leak MACsec keys over theCVE-2021-28509 · Arista EOS (TerminAttr / OpenConfig telemetry transport)Medium
- IBM OpenBMC OP910 web UI (phosphor-webui lineage): Stored/reflected script injection in the BMC web interfaceCVE-2021-38961 · IBM OpenBMC OP910 web UI (phosphor-webui lineage)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.