A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.
No analysis available yet.
Vendor Solution
Update to the Lenovo XClarity Administrator (LXCA) version (or higher) as recommended in the advisory: https://support.lenovo.com/us/en/product_security/LEN-136592 Follow general security best practices, such as limiting access to only trusted users within the environment. Only grant LXCA remote console/mount privileges to trusted administrative users.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54458 | A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information. |
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-136592 |
|
No history.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-12T18:32:28.134Z
Reserved: 2023-08-29T15:54:52.890Z
Link: CVE-2023-4605
Updated: 2024-08-02T07:31:06.648Z
Status : Deferred
Published: 2024-04-05T21:15:08.003
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-4605
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:15:57Z
EUVD