Impact
The vulnerability lies in the predictable creation of temporary files in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and earlier. An attacker with local, low‑privileged access can run the program under elevated privileges, causing the created temporary file to be named in a predictable manner. The attacker can then create or link a symlink to a target file before the temporary file is written, leading to overwrite or truncation of arbitrary local files. The weakness belongs to CWE‑377: Insecure Temporary File Creation. The impact manifests as local file corruption or deletion, potentially affecting system or application integrity if critical files are targeted.
Affected Systems
The affected product is Lenovo XClarity Essentials OneCLI version 5.5.0 and earlier, running on Linux operating systems. Users running these versions as sudo or root, or executing OneCLI with elevated privileges, are at risk. The advisory specifies a fix in later releases; therefore only the 5.5.0 release line and older should be considered vulnerable.
Risk and Exploitability
The CVSS score is 1, indicating low severity, but the EPSS score is not available, so the likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. The attack vector requires local presence; the attacker must be able to execute OneCLI and gain elevated privileges in the system. Since the flaw permits arbitrary file overwrite, once the prerequisite privileges are met, the exploit is straightforward. Administrators should consider this a low‑likelihood yet potentially damaging local attack.
OpenCVE Enrichment