Remote Mount Feature Vulnerability in Lenovo Products
CVE-2022-34888

2.7LOW

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
30 January 2023

Summary

A vulnerability in Lenovo’s Remote Mount feature can be exploited by authenticated users to establish connections to internal services that are typically restricted. This flaw may allow users to bypass established access controls, potentially exposing sensitive internal resources.

Affected Version(s)

Lenovo XClarity Controller various

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.