CVE-2018-16097Unrestricted File Upload in Lenovo Lxci FOR Microsoft System Center

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 68.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 30
Latest updateMay 14

Description

LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system file due to insufficient sanitization during the upload of a certificate.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5lenovo/lxci_for_microsoft_system_centerunspecified3.5
CVEListV5lenovo/lxci_for_vmwareunspecified5.5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g4v6-2497-jh7q: LXCI for VMware versions prior to 52022-05-14
CVEList
LXCI for VMware and LXCI for Microsoft System Center2018-11-30
CVE-2018-16097 — Unrestricted File Upload in Lenovo | cvebase