Lenovo XClarity Controller(XCC)是中国联想(Lenovo)公司的一款服务器嵌入式管理引擎,它主要用于标准化和自动化基础服务器管理任务。 Lenovo XClarity Controller 存在SQL注入漏洞,该漏洞源于经过身份验证的具有提升权限的 XCC 用户可以通过精心设计的 API 命令在有限的情况下执行 SQL 盲注。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Lenovo | Lenovo XClarity Controller (XCC) | various | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-4606 | 8.1 HIGH | Lenovo XClarity Controller 安全漏洞 |
| CVE-2023-3112 | 7.8 HIGH | Lenovo ThinkPad T14 Gen 3 安全漏洞 |
| CVE-2022-3699 | 7.8 HIGH | Lenovo Diagnostics 缓冲区错误漏洞 |
| CVE-2023-4607 | 7.5 HIGH | Lenovo XClarity Controller 安全漏洞 |
| CVE-2022-0353 | 4.4 MEDIUM | Lenovo Vantage 资源管理错误漏洞 |
| CVE-2022-3698 | 4.4 MEDIUM | Lenovo Diagnostics 资源管理错误漏洞 |
No comments yet