Database/Firmware, BMC & network fabric
Lenovo XClarity Administrator (LXCA, insufficient authorization): An authenticated LXCA user without sufficient
CVE-2024-45104Firmware, BMC & network fabriccurated
Impact
An authenticated LXCA user without sufficient privileges modifies a managed device through a crafted web API call using the device identifier - a horizontal privilege bypass over the fleet management API.
Who can reach it
Authenticated low-privilege LXCA user.
What to do
Apply the LXCA update per LEN-154748. Appliance upgrade; review LXCA role assignments while you are in there.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.