Impact
The Lenovo XClarity Integrator for Microsoft Windows Admin Center plugin, versions 5.1.1 and earlier, allows PowerShell Command Injection when establishing remote PowerShell commands. This vulnerability matches CWE-78 and enables an attacker to execute arbitrary commands on the host running the Windows Admin Center gateway, potentially compromising confidentiality, integrity, and availability of the system and any resources it manages.
Affected Systems
Lenovo XClarity Integrator for Microsoft Windows Admin Center, version 5.1.1 and earlier, when installed on the Windows Admin Center gateway.
Risk and Exploitability
With a CVSS score of 8.8, this flaw is considered high severity. The EPSS score of <1% indicates a low but non-zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via PowerShell commands executed through the Windows Admin Center gateway. An attacker with the ability to send or manipulate such remote PowerShell commands could gain full control over the underlying system, and due to the lack of current exploitation data the exploitation remains undetected in the public domain as of this analysis.
OpenCVE Enrichment