Unauthenticated Device Modification via API in LXCA
An authenticated LXCA user with valid credentials but without enough privileges might be able to change an LXCA managed device. This can happen through a specially crafted web API call using the device identifier.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
lenovo xclarity administrator |