Database/Firmware, BMC & network fabric
Lenovo XClarity OneCLI: temp file handling lets a local user overwrite files when the tool runs elevated
Impact
OneCLI is the tool operators run on Lenovo servers to inventory hardware, apply firmware updates and push BMC/UEFI settings, and it is normally invoked as root. Its temporary file creation on Linux lets an unprivileged local account on the same host cause OneCLI to overwrite or truncate arbitrary files with data the program itself generates. The attacker does not choose the content, so this is a corruption and denial-of-service primitive rather than a direct route to code execution - but on a management or provisioning host that runs firmware jobs for a fleet, destroying the wrong file can take out the tooling that drains and reflashes nodes. Lenovo scores it 1.0: it needs a local foothold and it needs an administrator to run OneCLI while the attacker is positioned.
Who can reach it
A local, authenticated low-privileged user on the Linux host where OneCLI is installed. Exploitation depends on an elevated OneCLI run happening (user interaction is in the vector), so the exposure is on shared management or bastion hosts rather than on a single-admin box.
What to do
Lenovo lists 5.5.0 and below as affected; upgrade to the fixed OneCLI release named in HT116433 - the record does not state the version number, so read it off the advisory. This is a management utility, not a daemon: replacing the binary needs no server downtime, no firmware flash and no node reboot. Interim mitigation is to stop non-administrators from having shell access on hosts where OneCLI is run elevated.
References
Related entries
- Wiwynn / Celestica / Ingrasys (Foxconn) / AIC BMC firmware: This vendor's firmware is unmeasurable from public dataNCVD-2026-015-wiwynn-celestica-ingrasys-foxcon · Wiwynn / Celestica / Ingrasys (Foxconn) / AIC BMC firmwareUnscored
- Xen on older AMD CPUs - 64-bit PV guest processor erratum: Xen 4.0 and 4.1 running a 64-bit PV guest on older AMD CPUsCVE-2012-2934 · Xen on older AMD CPUs - 64-bit PV guest processor erratumUnscored
- AMD 16h processor microcode - locked instructions vs write-combined memory: Interaction between locked instructionsCVE-2013-6885 · AMD 16h processor microcode - locked instructions vs write-combined memoryUnscored
- Juniper Junos OS MACsec key configuration (CKN/CAK): If you configure a MACsec connectivity-association name or keyCVE-2018-0021 · Juniper Junos OS MACsec key configuration (CKN/CAK)Unscored
- swtpm (state blob header parsing): An invalid hdrsize in swtpm's saved state header causes an out-of-bounds accessCVE-2022-23645 · swtpm (state blob header parsing)Unscored
- Supermicro BMC (IPMI web interface): Part of the same 2023 Supermicro BMC web-interface batchCVE-2023-40286 · Supermicro BMC (IPMI web interface)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.