CVE-2024-8280

EUVD-2024-49064
An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection or cause a recoverable denial of service using a specially crafted file.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 61%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
lenovothinkagile_hx7530_firmware
𝑥
< 4.71_afbt48c
ADP
lenovothinksystem_st250_v3_firmware
𝑥
< 2.10_ctx213g
ADP
lenovothinkagile_hx1320_firmware
𝑥
< 9.97_cdi3b4b
ADP
lenovothinkagile_hx3375_firmware
𝑥
< 5.61_d8bt64d
ADP
lenovothinkagile_hx_enclosure_certified_node_firmware
𝑥
< 6.36_tei3f4a
ADP
lenovothinkagile_hx1021_edge_certified_node_3yr_firmware
𝑥
< 4.11_tei3e4a
ADP
lenovothinkagile_hx7820_firmware
𝑥
< 3.11_psi354a
ADP
lenovothinksystem_sd530_v3_firmware
𝑥
< 1.20_usx352
ADP
lenovothinksystem_sd630_v2_firmware
𝑥
< 4.11_tgbt50c
ADP
lenovothinksystem_st650_v3_firmware
𝑥
< 6.10_usx350g
ADP
lenovothinksystem_sr675_v3_firmware
𝑥
< 6.10_qgx340j
ADP
lenovothinkedge_se350_v2_firmware
𝑥
< 3.11_iyx328m
ADP
lenovothinkedge_se450__firmware
𝑥
< 3.11_usx332x
ADP
lenovothinkedge_se455_v3_firmware
𝑥
< 3.10_mbx308l
ADP
lenovothinksystem_sr630_v3_firmware
𝑥
< 5.10_esx330m
ADP
lenovothinksystem_sr635_v3_firmware
𝑥
< 3.20_kax334o
ADP
lenovothinksystem_sr850_v3_firmware
𝑥
< 4.10_rsx312i
ADP
lenovothinksystem_sr950_v3_firmware
𝑥
< 3.10_ebx308i
ADP