6.5
CVSSv3

CVE-2024-45104

CVSSv4: NA | CVSSv3: 6.5 | CVSSv2: NA | VMScore: 750 | EPSS: 0.00051 | KEV: Not Included
Published: 13/09/2024 Updated: 13/12/2024

Vulnerability Summary

Unauthenticated Device Modification via API in LXCA

An authenticated LXCA user with valid credentials but without enough privileges might be able to change an LXCA managed device. This can happen through a specially crafted web API call using the device identifier.

Vulnerable Product Search on Vulmon Subscribe to Product

lenovo xclarity administrator