Description

An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a device on the local Lenovo XClarity Orchestrator (LXCO) network segment may be able to manipulate the local device to create an alternate communication channel which could allow the attacker, under certain conditions, to directly interact with backend LXCO API services typically inaccessible to users. While access controls may limit the scope of interaction, this could result in unauthorized access to internal functionality or data. This issue is not exploitable from remote networks.

INFO

Published Date :

2025-09-11T18:34:27.875Z

Last Modified :

2025-09-11T18:56:07.128Z

Source :

lenovo
AFFECTED PRODUCTS

The following products are affected by CVE-2025-8557 vulnerability.

Vendors Products
Lenovo
  • Xclarity Orchestrator
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-8557.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact