A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands.
https://support.lenovo.com/us/en/product_security/LEN-156781