CVE-2017-3770: High severity lenovo xclarity administrator vulnerability
Published Sep 22, 2017
·Updated
Privilege escalation vulnerability in LXCA versions earlier than 1.3.2 where an authenticated user may be able to abuse certain web interface functionality to execute privileged commands within the underlying LXCA operating system.
Affected Software
1 affected component
Lenovo XClarity Administrator<=1.3.1
Event History
Sep 22, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-3770?
CVE-2017-3770 has been classified as a privilege escalation vulnerability.
2
How do I fix CVE-2017-3770?
To fix CVE-2017-3770, upgrade to Lenovo XClarity Administrator version 1.3.2 or later.
3
Who is affected by CVE-2017-3770?
CVE-2017-3770 affects authenticated users of Lenovo XClarity Administrator versions earlier than 1.3.2.
4
What types of attacks can be performed using CVE-2017-3770?
CVE-2017-3770 allows an authenticated user to execute privileged commands through certain web interface functionalities.
5
Is CVE-2017-3770 a remote or local vulnerability?
CVE-2017-3770 is a local vulnerability that requires authenticated access to exploit.