CVE-2023-3113: An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in...

8.2 CVSS

Description

An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files.

Classification

CVE ID: CVE-2023-3113

CVSS Base Severity: HIGH

CVSS Base Score: 8.2

Affected Products

Vendor: Lenovo

Product: Lenovo XClarity Administrator

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.12% (probability of being exploited)

EPSS Percentile: 46.7% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://support.lenovo.com/us/en/product_security/LEN-98715

Timeline