CVE-2024-8281

EUVD-2024-49065
An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection through specially crafted command line input in the XCC SSH captive shell.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
lenovothinkagile_hx7530_firmware
𝑥
< 4.71_afbt48c
ADP
lenovothinksystem_st250_v3_firmware
𝑥
< 2.10_ctx213g
ADP
lenovothinkagile_hx1320_firmware
𝑥
< 9.97_cdi3b4b
ADP
lenovothinkagile_hx3375_firmware
𝑥
< 5.61_d8bt64d
ADP
lenovothinkagile_hx_enclosure_certified_node_firmware
𝑥
< 6.36_tei3f4a
ADP
lenovothinkagile_hx1021_edge_certified_node_3yr_firmware
𝑥
< 4.11_tei3e4a
ADP
lenovothinkagile_hx7820_firmware
𝑥
< 3.11_psi354a
ADP
lenovothinksystem_sd530_v3_firmware
𝑥
< 1.20_usx352
ADP
lenovothinksystem_sd630_v2_firmware
𝑥
< 4.11_tgbt50c
ADP
lenovothinksystem_st650_v3_firmware
𝑥
< 6.10_usx350g
ADP
lenovothinksystem_sr675_v3_firmware
𝑥
< 6.10_qgx340j
ADP
lenovothinkedge_se350_v2_firmware
𝑥
< 3.11_iyx328m
ADP
lenovothinkedge_se450__firmware
𝑥
< 3.11_usx332x
ADP
lenovothinkedge_se455_v3_firmware
𝑥
< 3.10_mbx308l
ADP
lenovothinksystem_sr630_v3_firmware
𝑥
< 5.10_esx330m
ADP
lenovothinksystem_sr635_v3_firmware
𝑥
< 3.20_kax334o
ADP
lenovothinksystem_sr850_v3_firmware
𝑥
< 4.10_rsx312i
ADP
lenovothinksystem_sr950_v3_firmware
𝑥
< 3.10_ebx308i
ADP