A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentication/authorization and logins configured as “Local First, then LDAP”.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-32660 A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentication/authorization and logins configured as “Local First, then LDAP”.
Fixes

Solution

Customers should update to the version (or later) of Lenovo XClarity Controller (XCC) identified in the related Lenovo Product Security Advisory:  https://support.lenovo.com/us/en/product_security/LEN-118321 https://support.lenovo.com/us/en/product_security/LEN-118321


Workaround

No workaround given by the vendor.

History

Thu, 30 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2025-01-30T18:34:12.946Z

Reserved: 2023-03-30T12:46:45.646Z

Link: CVE-2023-29057

cve-icon Vulnrichment

Updated: 2024-08-02T14:00:15.127Z

cve-icon NVD

Status : Modified

Published: 2023-04-28T21:15:08.673

Modified: 2024-11-21T07:56:28.157

Link: CVE-2023-29057

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.