Impact
A flaw allowing certain special characters in OS profile passwords to pass through the system’s command interpreter creates an OS command injection vulnerability. The weakness is a classic example of insecure input handling and command execution, exposing both CWE-78 and CWE-20. An attacker who is authenticated and holds privileged rights on the Lenovo XClarity Orchestrator can trigger arbitrary operating‑system commands as that privileged user, jeopardizing confidentiality by allowing data read or exfiltration, integrity by modifying system state, and availability by potentially disrupting services if destructive commands are executed.
Affected Systems
Lenovo XClarity Orchestrator version 2.2.0 is affected. No other product or version information is provided in the current report.
Risk and Exploitability
The CVSS score of 8.7 indicates a high‑severity vulnerability. Although the EPSS score is not available and it is not listed in CISA’s KEV catalog, the requirement for authenticated privileged access means that only users with sufficient permissions can exploit the flaw. Likely exploitation would occur through the orchestration web interface or APIs when an attacker supplies a specially crafted OS profile password that is interpreted as an OS command. The combination of high severity and the necessity of privileged credentials makes the risk substantial for environments that host the unpatched LXCO deployment.
OpenCVE Enrichment