A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://support.lenovo.com/us/en/product_security/LEN-154748 |
History
Thu, 19 Sep 2024 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Emc
Emc vmware Lenovo Lenovo xclarity Administrator Microsoft Microsoft windows Redhat Redhat kernel-based Virtual Machine |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:emc:vmware:-:*:*:*:*:*:*:* cpe:2.3:a:lenovo:xclarity_administrator:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:o:redhat:kernel-based_virtual_machine:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Emc
Emc vmware Lenovo Lenovo xclarity Administrator Microsoft Microsoft windows Redhat Redhat kernel-based Virtual Machine |
Fri, 13 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 13 Sep 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call. | |
Weaknesses | CWE-282 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: lenovo
Published: 2024-09-13T17:28:55.910Z
Updated: 2024-09-13T17:48:48.901Z
Reserved: 2024-08-21T19:24:36.785Z
Link: CVE-2024-45104
Vulnrichment
Updated: 2024-09-13T17:48:44.043Z
NVD
Status : Analyzed
Published: 2024-09-13T18:15:05.087
Modified: 2024-09-19T01:49:50.870
Link: CVE-2024-45104
Redhat
No data.