An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to higher-privileged information if 1) “LDAP Authentication Only with Local Authorization” mode is configured and used by XCC, and 2) a lesser privileged user logs into XCC within 1 minute of a higher privileged user logging out. The authorization bypass does not exist when “Local Authentication and Authorization” or “LDAP Authentication and Authorization” modes are configured and used by XCC.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Lenovo
Subscribe
|
Thinkagile Hx 1000
Subscribe
Thinkagile Hx 2000
Subscribe
Thinkagile Hx 3000
Subscribe
Thinkagile Hx 5000
Subscribe
Thinkagile Hx 7000
Subscribe
Thinkagile Mx Sr650
Subscribe
Thinkagile Vx 1000
Subscribe
Thinkagile Vx 2000
Subscribe
Thinkagile Vx 3000
Subscribe
Thinkagile Vx 5000
Subscribe
Thinkagile Vx 7000
Subscribe
Thinksystem Sd530
Subscribe
Thinksystem Sd650 Dwc
Subscribe
Thinksystem Sn550
Subscribe
Thinksystem Sn850
Subscribe
Thinksystem Sr150
Subscribe
Thinksystem Sr158
Subscribe
Thinksystem Sr250
Subscribe
Thinksystem Sr258
Subscribe
Thinksystem Sr530
Subscribe
Thinksystem Sr550
Subscribe
Thinksystem Sr570
Subscribe
Thinksystem Sr590
Subscribe
Thinksystem Sr630
Subscribe
Thinksystem Sr650
Subscribe
Thinksystem Sr850
Subscribe
Thinksystem Sr860
Subscribe
Thinksystem Sr950 Server
Subscribe
Thinksystem St250
Subscribe
Thinksystem St258
Subscribe
Thinksystem St550
Subscribe
Thinksystem St558
Subscribe
Xclarity Controller
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-15762 | An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to higher-privileged information if 1) “LDAP Authentication Only with Local Authorization” mode is configured and used by XCC, and 2) a lesser privileged user logs into XCC within 1 minute of a higher privileged user logging out. The authorization bypass does not exist when “Local Authentication and Authorization” or “LDAP Authentication and Authorization” modes are configured and used by XCC. |
Fixes
Solution
Update to Lenovo XClarity Controller (XCC) version 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N or higher.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-29116 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-09-16T16:14:10.788Z
Reserved: 2019-01-11T00:00:00
Link: CVE-2019-6195
No data.
Status : Modified
Published: 2020-02-14T17:15:13.223
Modified: 2024-11-21T04:46:09.123
Link: CVE-2019-6195
No data.
OpenCVE Enrichment
No data.
EUVD