Lenovo XClarity Orchestrator
cpe:2.3:a:lenovo:xclarity_orchestrator:*:*:*:*:*:*:*
A vulnerability in Lenovo XClarity Orchestrator (LXCO) has been identified, allowing an attacker with access to a local device on the LXCO network segment to create an alternate communication channel. This could enable direct interaction with backend LXCO API services that are usually inaccessible to users. Although access controls might restrict the extent of this interaction, it could lead to unauthorized access to internal functionality or data. This vulnerability cannot be exploited from remote networks.
Exploitation of this vulnerability could result in unauthorized access to internal LXCO functionality or data.
Users are advised to update to Lenovo XClarity Orchestrator version 2.2.0 or newer. For update instructions, visit the Lenovo Drivers & Software support site or refer to Lenovo's update management tools for PC Products and Software or Server and Enterprise Software.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.