LXCA
by Lenovo
CVEs (8)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-3113 | Hig | 0.53 | 8.2 | 0.01 | Jun 26, 2023 | An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files. | ||
| CVE-2023-34418 | Hig | 0.53 | 8.1 | 0.01 | Jun 26, 2023 | A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API. | ||
| CVE-2023-34420 | Hig | 0.47 | 7.2 | 0.01 | Jun 26, 2023 | A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API. | ||
| CVE-2024-45102 | Med | 0.44 | 6.8 | 0.00 | Jan 14, 2025 | A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their permissions for a connected XCC instance when using LXCA as a Single Sign On (SSO) provider for XCC instances. | ||
| CVE-2023-34422 | Med | 0.42 | 6.5 | 0.00 | Jun 26, 2023 | A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation. | ||
| CVE-2023-34421 | Med | 0.42 | 6.5 | 0.00 | Jun 26, 2023 | A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation. | ||
| CVE-2024-45104 | Med | 0.41 | 6.3 | 0.00 | Sep 13, 2024 | A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call. | ||
| CVE-2024-45103 | Med | 0.28 | 4.3 | 0.00 | Sep 13, 2024 | A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges. |
- risk 0.53cvss 8.2epss 0.01
An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files.
- risk 0.53cvss 8.1epss 0.01
A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API.
- risk 0.47cvss 7.2epss 0.01
A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API.
- risk 0.44cvss 6.8epss 0.00
A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their permissions for a connected XCC instance when using LXCA as a Single Sign On (SSO) provider for XCC instances.
- risk 0.42cvss 6.5epss 0.00
A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation.
- risk 0.42cvss 6.5epss 0.00
A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation.
- risk 0.41cvss 6.3epss 0.00
A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.
- risk 0.28cvss 4.3epss 0.00
A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.