VYPR
Medium severity6.3NVD Advisory· Published Sep 13, 2024· Updated Jun 17, 2026

CVE-2024-45104

CVE-2024-45104

Description

A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.

Affected products

3
  • cpe:2.3:a:lenovo:xclarity_administrator:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:lenovo:xclarity_administrator:*:*:*:*:*:*:*:*range: <4.1.0
    • (no CPE)range: 0
  • Lenovo/LXCAllm-fuzzy

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.