CVE-2023-4605: Medium severity Lenovo XClarity Administrator vulnerability
Published Apr 5, 2024
·Updated
A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.
Affected Software
1 affected component
Lenovo XClarity Administrator
Remediation
Information
Update to the Lenovo XClarity Administrator (LXCA) version (or higher) as recommended in the advisory: https://support.lenovo.com/us/en/product_security/LEN-136592
Follow general security best practices, such as limiting access to only trusted users within the environment.
Only grant LXCA remote console/mount privileges to trusted administrative users.
Event History
Apr 5, 2024
CVE Published
via MITRE·08:44 PM
Data Sourced
via MITRE·08:44 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-4605?
CVE-2023-4605 has been classified as a high severity vulnerability.
2
How do I fix CVE-2023-4605?
To fix CVE-2023-4605, ensure that you restrict access to the vulnerable API endpoint and apply any available patches from Lenovo.
3
Who is affected by CVE-2023-4605?
CVE-2023-4605 affects users of Lenovo XClarity Administrator who have authenticated access.
4
What is the potential impact of CVE-2023-4605?
The potential impact of CVE-2023-4605 is that an authenticated user may be able to access sensitive system event information without proper authorization.
5
When was CVE-2023-4605 disclosed?
CVE-2023-4605 was disclosed on October 19, 2023.