A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-54458 A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.
Fixes

Solution

Update to the Lenovo XClarity Administrator (LXCA) version (or higher) as recommended in the advisory:  https://support.lenovo.com/us/en/product_security/LEN-136592 Follow general security best practices, such as limiting access to only trusted users within the environment. Only grant LXCA remote console/mount privileges to trusted administrative users.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-12T18:32:28.134Z

Reserved: 2023-08-29T15:54:52.890Z

Link: CVE-2023-4605

cve-icon Vulnrichment

Updated: 2024-08-02T07:31:06.648Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-05T21:15:08.003

Modified: 2024-11-21T08:35:31.717

Link: CVE-2023-4605

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:15:57Z