{"api_version":"1","generated_at":"2026-07-23T09:52:21+00:00","cve":"CVE-2017-3770","urls":{"html":"https://cve.report/CVE-2017-3770","api":"https://cve.report/api/cve/CVE-2017-3770.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-3770","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-3770"},"summary":{"title":"CVE-2017-3770","description":"Privilege escalation vulnerability in LXCA versions earlier than 1.3.2 where an authenticated user may be able to abuse certain web interface functionality to execute privileged commands within the underlying LXCA operating system.","state":"PUBLIC","assigner":"psirt@lenovo.com","published_at":"2017-09-22 14:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://support.lenovo.com/us/en/product_security/LEN-16333","name":"https://support.lenovo.com/us/en/product_security/LEN-16333","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Attacker with Access to LXCA Filesystem Could Access Local LXCA Account Credentials and LXCA Authenticated Command Injection - Lenovo Support US","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-3770","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-3770","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"3770","vulnerable":"1","versionEndIncluding":"1.3.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"lenovo","cpe5":"xclarity_administrator","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@lenovo.com","DATE_PUBLIC":"2017-09-21T00:00:00","ID":"CVE-2017-3770","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Lenovo XClarity Administrator (LXCA)","version":{"version_data":[{"version_value":"Earlier than 1.3.2"}]}}]},"vendor_name":"Lenovo Group Ltd."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Privilege escalation vulnerability in LXCA versions earlier than 1.3.2 where an authenticated user may be able to abuse certain web interface functionality to execute privileged commands within the underlying LXCA operating system."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Privilege Escalation"}]}]},"references":{"reference_data":[{"name":"https://support.lenovo.com/us/en/product_security/LEN-16333","refsource":"CONFIRM","url":"https://support.lenovo.com/us/en/product_security/LEN-16333"}]}},"nvd":{"publishedDate":"2017-09-22 14:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:lenovo:xclarity_administrator:*:*:*:*:*:*:*:*","versionEndIncluding":"1.3.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"3770","Ordinal":"100152","Title":"CVE-2017-3770","CVE":"CVE-2017-3770","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"3770","Ordinal":"1","NoteData":"Privilege escalation vulnerability in LXCA versions earlier than 1.3.2 where an authenticated user may be able to abuse certain web interface functionality to execute privileged commands within the underlying LXCA operating system.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"3770","Ordinal":"2","NoteData":"2017-09-22","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"3770","Ordinal":"3","NoteData":"2017-09-22","Type":"Other","Title":"Modified"}]}}}