Products
Lenovo XClarity Controller
Source
psirt@lenovo.com
Tags
CVE-2024-45101 details
Published : Sept. 13, 2024, 6:15 p.m.
Last Modified : Sept. 13, 2024, 6:15 p.m.
Last Modified : Sept. 13, 2024, 6:15 p.m.
Description
A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, authenticated LXCA user’s XCC session if they can convince the user to click on a specially crafted URL.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6.8 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|---|---|
CWE-319 | Cleartext Transmission of Sensitive Information | The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. |
CVSS Data
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
6.8
Exploitability Score
1.6
Impact Score
5.2
Base Severity
MEDIUM
Vector String : CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
References
URL | Source |
---|---|
https://support.lenovo.com/us/en/product_security/LEN-154748 | psirt@lenovo.com |
This website uses the NVD API, but is not approved or certified by it.