Database/Firmware, BMC & network fabric
Lenovo XClarity Orchestrator: microservices accept invalid TLS certificates, exposing management traffic
Impact
XClarity Orchestrator aggregates out-of-band management for Lenovo server fleets and holds the credentials it uses to drive XCC BMCs. Several 2.2.0 microservices do not properly validate TLS certificates, so an attacker positioned on the management network can machine-in-the-middle those HTTPS connections and read what crosses them. Lenovo qualifies this as happening 'under certain circumstances' and does not enumerate which microservices or which flows are affected, so treat exposure of management credentials as plausible rather than established. In a datacenter that runs out-of-band management flat across racks, this is exactly the segment an attacker with one rack-level foothold would be sitting on.
Who can reach it
Adjacent network - an attacker able to position on the management network segment LXCO uses. No authentication to LXCO is required.
What to do
Upgrade XClarity Orchestrator per Lenovo advisory HT509976 and restart the appliance; the NVD record does not name the fixed build, so take the version from Lenovo's page. This touches management-plane software only - no BMC or server firmware flash, no node reboot, no drain. Until the upgrade lands, the mitigation is network-level: keep the management VLAN isolated from tenant and general corporate traffic.
References
Related entries
- Intel TDX module, Ring 0 / Trust Domain context, multiple Intel platforms - INTEL-SA-01436: Improper authenticationCVE-2026-20885 · Intel TDX module, Ring 0 / Trust Domain context, multiple Intel platforms - INTEL-SA-01436High
- GRUB2 (USB device initialization): Out-of-bounds write in grub_usb_device_initialize from a malicious USB descriptorCVE-2020-25647 · GRUB2 (USB device initialization)Medium
- AMD Secure Processor PCI driver - input validation: Improper input validation in the ASP PCI driver lets a localCVE-2025-0045 · AMD Secure Processor PCI driver - input validationMedium
- AMD SEV firmware - RMP write during SNP initialization: A privileged attacker can write to the reverse map page duringCVE-2025-29939 · AMD SEV firmware - RMP write during SNP initializationMedium
- AMD Secure Processor PCI driver - use-after-free: A use-after-free reachable through the ASP PCI driverCVE-2025-48521 · AMD Secure Processor PCI driver - use-after-freeMedium
- IBM Power Systems FSP: authenticated admin can force a persistent degraded operating modeCVE-2026-16938 · IBM Power Systems Firmware (FSP privileged system configuration controls)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.