Database/Firmware, BMC & network fabric
Lenovo XClarity Orchestrator (alternate communication channel): An attacker on the LXCO network segment manipulates
CVSS 8.8CVE-2025-8557Firmware, BMC & network fabriccurated
Impact
An attacker on the LXCO network segment manipulates a local device to create an alternate communication channel into the management stack - a network-position attack against the fleet controller.
Who can reach it
Access to a device on the LXCO local network segment. Unauthenticated.
What to do
Apply the LXCO update per LEN-201014, and put the orchestrator on a dedicated management segment rather than a shared server VLAN.
References
Related entries
- Lenovo XClarity Integrator for Windows Admin Center (PowerShell command injection): PowerShell command injectionCVE-2026-14371 · Lenovo XClarity Integrator for Windows Admin Center (PowerShell command injection)High
- OpenBMC phosphor-net-ipmid: session authorization can be swapped to another account without re-authenticatingCVE-2026-16140 · OpenBMC phosphor-net-ipmid (IPMI 2.0 RAKP session authorization)High
- Lenovo XClarity Orchestrator (OS command injection): An authenticated attacker executes arbitrary OS commandsCVE-2026-16793 · Lenovo XClarity Orchestrator (OS command injection)High
- Eaton Tripp Lite series PADM firmware, session management interface: A low-privilege authenticated user escalatesCVE-2026-22622 · Eaton Tripp Lite series PADM firmware, session management interfaceHigh
- NVIDIA UFM Enterprise: web interface authorization flaw leads to code execution on the fabric managerCVE-2026-24170 · NVIDIA UFM Enterprise (web interface authorization)High
- Linux kernel (drivers/infiniband/core): The RDMA user-capability check identified the capability file only by deviceCVE-2026-53188 · Linux kernel (drivers/infiniband/core)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.