Impact
The vulnerability is an improper TLS certificate validation in Lenovo XClarity Orchestrator microservices. This flaw allows an attacker on the same local network segment to perform a man‑in‑the‑middle attack and intercept or modify HTTPS traffic, potentially exposing credentials and configuration data.
Affected Systems
Affected systems are Lenovo XClarity Orchestrator microservices, specifically version 2.2.0.
Risk and Exploitability
The CVSS score is 7, indicating a high severity. EPSS is not available, and the vulnerability is not listed in KEV, suggesting no public exploits are known. The likely attack vector is an adjacent local network attacker that can reach the orchestrator's service endpoints. Because proper certificate verification is bypassed, the system can be coerced into trusting a forged certificate, enabling the attacker to decrypt or alter traffic.
OpenCVE Enrichment