CVE-2024-38511OS Command Injection in Lenovo Xclarity Controller

Severity
7.2HIGHNVD
EPSS
0.5%
top 35.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 26

Description

A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages1 packages

CVEListV5lenovo/xclarity_controllervarious

🔴Vulnerability Details

2
CVEList
CVE-2024-38511: A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an authenticated XCC user with eleva2024-07-26
GHSA
GHSA-q6hr-rj2r-76hq: A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an authenticated XCC user with eleva2024-07-26
CVE-2024-38511 — OS Command Injection in Lenovo | cvebase