Database/Firmware, BMC & network fabric
Lenovo XClarity Orchestrator (alternate communication channel): An attacker on the LXCO network segment manipulates
CVE-2025-8557Firmware, BMC & network fabriccurated
Impact
An attacker on the LXCO network segment manipulates a local device to create an alternate communication channel into the management stack - a network-position attack against the fleet controller.
Who can reach it
Access to a device on the LXCO local network segment. Unauthenticated.
What to do
Apply the LXCO update per LEN-201014, and put the orchestrator on a dedicated management segment rather than a shared server VLAN.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.