CVE-2024-45104: Medium severity lenovo xclarity administrator vulnerability
Published Sep 13, 2024
·Updated
A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.
Affected Software
1 affected component
Lenovo XClarity Administrator<4.1.0
Remediation
Information
Update Lenovo XClarity Administrator to the version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-154748
Event History
Sep 13, 2024
CVE Published
via MITRE·05:28 PM
Data Sourced
via MITRE·05:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-45104?
CVE-2024-45104 is categorized as a medium severity vulnerability.
2
How do I fix CVE-2024-45104?
To mitigate CVE-2024-45104, ensure that all users have the appropriate privileges and apply all available updates for Lenovo XClarity Administrator.
3
Who is affected by CVE-2024-45104?
Users of Lenovo XClarity Administrator versions prior to 4.1.0 are affected by CVE-2024-45104.
4
What type of access is exploited in CVE-2024-45104?
CVE-2024-45104 allows an authenticated LXCA user to modify managed devices using a specially crafted web API call.
5
Is there a workaround for CVE-2024-45104?
A potential workaround for CVE-2024-45104 includes restricting user privileges to limit API access.