GPU VulnDB

Database/Firmware, BMC & network fabric

Lenovo XClarity Orchestrator (alternate communication channel): An attacker on the LXCO network segment manipulates

CVE-2025-8557Firmware, BMC & network fabriccurated

Impact

An attacker on the LXCO network segment manipulates a local device to create an alternate communication channel into the management stack - a network-position attack against the fleet controller.

Who can reach it

Access to a device on the LXCO local network segment. Unauthenticated.

What to do

Apply the LXCO update per LEN-201014, and put the orchestrator on a dedicated management segment rather than a shared server VLAN.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.