Lenovo

Xclarity Orchestrator

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 04.08.2026 20:16:49
  • Zuletzt bearbeitet 24.08.2026 16:45:25

An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middl...

  • EPSS 0.36%
  • Veröffentlicht 04.08.2026 20:16:49
  • Zuletzt bearbeitet 24.08.2026 16:45:25

An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a ...

  • EPSS 0.25%
  • Veröffentlicht 11.09.2025 18:34:27
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a device on the local Lenovo XClarity Orchestrator (LXCO) network segment may be able to manipulate the local de...

  • EPSS 0.54%
  • Veröffentlicht 09.03.2021 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:38:46

An internal product security audit of LXCO, prior to version 1.2.2, discovered that optional passwords, if specified, for the Syslog and SMTP forwarders are written to an internal LXCO log file in clear text. Affected logs are captured in the First F...

  • EPSS 0.54%
  • Veröffentlicht 09.03.2021 17:15:12
  • Zuletzt bearbeitet 21.11.2024 06:21:27

An internal product security audit of LXCO, prior to version 1.2.2, discovered that credentials for Lenovo XClarity Administrator (LXCA), if added as a Resource Manager, are encoded then written to an internal LXCO log file each time a session is est...