XCC Vulnerability in Lenovo Product Allows Unauthorized Role Modification
CVE-2023-29058
6.4MEDIUM
What is CVE-2023-29058?
An improperly configured access control in Lenovo's XCC allows a valid authenticated user with read-only permissions to modify custom user roles for other accounts and alter trespass messages via the XCC CLI. This oversight can lead to unauthorized privilege escalation if SSH is enabled and read-only permissions are assigned to multiple users. It is essential to ensure that SSH is disabled or that proper user permissions are allocated to minimize risks.
Affected Version(s)
XClarity Controller Refer to Mitigation strategy section in LEN-118321