First published: Mon Jun 26 2023(Updated: )
An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo XClarity Administrator | <4.0.0 |
Update LXCA to version 4.0 or later.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3113 is an unauthenticated XML external entity injection (XXE) vulnerability in LXCA's Common Information Model (CIM) server.
CVE-2023-3113 has a severity rating of high, with a severity value of 7.5.
An attacker can exploit CVE-2023-3113 by injecting malicious XML entities into LXCA's Common Information Model (CIM) server to gain read-only access to specific files.
No, CVE-2023-3113 can be exploited without authentication.
To fix CVE-2023-3113, it is recommended to update Lenovo XClarity Administrator to version 4.0.1 or later.