A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-37383 | A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads. |
Fixes
Solution
Update to the version (or newer) indicated for your model in the Product Impact section in the advisory: https://support.lenovo.com/us/en/product_security/LEN-156781
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-156781 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-02T04:12:25.141Z
Reserved: 2024-06-18T14:42:40.470Z
Link: CVE-2024-38511
Updated: 2024-08-02T04:12:25.141Z
Status : Awaiting Analysis
Published: 2024-07-26T20:15:04.263
Modified: 2024-11-21T09:26:07.767
Link: CVE-2024-38511
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD