A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined.

Project Subscriptions

Vendors Products
Thinkagile Hx1021 Subscribe
Thinkagile Hx1021 Firmware Subscribe
Thinkagile Hx1320 Subscribe
Thinkagile Hx1320 Firmware Subscribe
Thinkagile Hx1321 Subscribe
Thinkagile Hx1321 Firmware Subscribe
Thinkagile Hx1331 Subscribe
Thinkagile Hx1331 Firmware Subscribe
Thinkagile Hx1520-r Subscribe
Thinkagile Hx1520-r Firmware Subscribe
Thinkagile Hx1521-r Subscribe
Thinkagile Hx1521-r Firmware Subscribe
Thinkagile Hx2320-e Subscribe
Thinkagile Hx2320-e Firmware Subscribe
Thinkagile Hx2321 Subscribe
Thinkagile Hx2321 Firmware Subscribe
Thinkagile Hx2330 Subscribe
Thinkagile Hx2330 Firmware Subscribe
Thinkagile Hx2331 Subscribe
Thinkagile Hx2331 Firmware Subscribe
Thinkagile Hx2720-e Subscribe
Thinkagile Hx2720-e Firmware Subscribe
Thinkagile Hx3320 Subscribe
Thinkagile Hx3320 Firmware Subscribe
Thinkagile Hx3321 Subscribe
Thinkagile Hx3321 Firmware Subscribe
Thinkagile Hx3330 Subscribe
Thinkagile Hx3330 Firmware Subscribe
Thinkagile Hx3331 Subscribe
Thinkagile Hx3331 Firmware Subscribe
Thinkagile Hx3375 Subscribe
Thinkagile Hx3375 Firmware Subscribe
Thinkagile Hx3376 Subscribe
Thinkagile Hx3376 Firmware Subscribe
Thinkagile Hx3520-g Subscribe
Thinkagile Hx3520-g Firmware Subscribe
Thinkagile Hx3521-g Subscribe
Thinkagile Hx3521-g Firmware Subscribe
Thinkagile Hx3720 Subscribe
Thinkagile Hx3720 Firmware Subscribe
Thinkagile Hx3721 Subscribe
Thinkagile Hx3721 Firmware Subscribe
Thinkagile Hx5520 Subscribe
Thinkagile Hx5520-c Subscribe
Thinkagile Hx5520-c Firmware Subscribe
Thinkagile Hx5520 Firmware Subscribe
Thinkagile Hx5521 Subscribe
Thinkagile Hx5521-c Subscribe
Thinkagile Hx5521-c Firmware Subscribe
Thinkagile Hx5521 Firmware Subscribe
Thinkagile Hx5530 Subscribe
Thinkagile Hx5530 Firmware Subscribe
Thinkagile Hx5531 Subscribe
Thinkagile Hx5531 Firmware Subscribe
Thinkagile Hx7520 Subscribe
Thinkagile Hx7520 Firmware Subscribe
Thinkagile Hx7521 Subscribe
Thinkagile Hx7521 Firmware Subscribe
Thinkagile Hx7530 Subscribe
Thinkagile Hx7530 Firmware Subscribe
Thinkagile Hx7531 Subscribe
Thinkagile Hx7531 Firmware Subscribe
Thinkagile Hx7820 Subscribe
Thinkagile Hx7820 Firmware Subscribe
Thinkagile Hx7821 Subscribe
Thinkagile Hx7821 Firmware Subscribe
Thinkagile Hx Enclosure Subscribe
Thinkagile Hx Enclosure Firmware Subscribe
Thinkagile Mx1020 Subscribe
Thinkagile Mx1020 Firmware Subscribe
Thinkagile Mx1021 On Se350 Subscribe
Thinkagile Mx1021 On Se350 Firmware Subscribe
Thinkagile Mx3330-f Subscribe
Thinkagile Mx3330-f Firmware Subscribe
Thinkagile Mx3330-h Subscribe
Thinkagile Mx3330-h Firmware Subscribe
Thinkagile Mx3331-f Subscribe
Thinkagile Mx3331-f Firmware Subscribe
Thinkagile Mx3331-h Subscribe
Thinkagile Mx3331-h Firmware Subscribe
Thinkagile Mx3530-h Subscribe
Thinkagile Mx3530-h Firmware Subscribe
Thinkagile Mx3530 F Subscribe
Thinkagile Mx3530 F Firmware Subscribe
Thinkagile Mx3531-f Subscribe
Thinkagile Mx3531-f Firmware Subscribe
Thinkagile Mx3531 H Subscribe
Thinkagile Mx3531 H Firmware Subscribe
Thinkagile Vx1320 Subscribe
Thinkagile Vx1320 Firmware Subscribe
Thinkagile Vx2320 Subscribe
Thinkagile Vx2320 Firmware Subscribe
Thinkagile Vx2330 Subscribe
Thinkagile Vx2330 Firmware Subscribe
Thinkagile Vx3320 Subscribe
Thinkagile Vx3320 Firmware Subscribe
Thinkagile Vx3330 Subscribe
Thinkagile Vx3330 Firmware Subscribe
Thinkagile Vx3331 Subscribe
Thinkagile Vx3331 Firmware Subscribe
Thinkagile Vx3520-g Subscribe
Thinkagile Vx3520-g Firmware Subscribe
Thinkagile Vx3530-g Subscribe
Thinkagile Vx3530-g Firmware Subscribe
Thinkagile Vx3720 Subscribe
Thinkagile Vx3720 Firmware Subscribe
Thinkagile Vx5520 Subscribe
Thinkagile Vx5520 Firmware Subscribe
Thinkagile Vx5530 Subscribe
Thinkagile Vx5530 Firmware Subscribe
Thinkagile Vx7320 N Subscribe
Thinkagile Vx7320 N Firmware Subscribe
Thinkagile Vx7330 Subscribe
Thinkagile Vx7330 Firmware Subscribe
Thinkagile Vx7520 Subscribe
Thinkagile Vx7520 Firmware Subscribe
Thinkagile Vx7520 N Subscribe
Thinkagile Vx7520 N Firmware Subscribe
Thinkagile Vx7530 Subscribe
Thinkagile Vx7530 Firmware Subscribe
Thinkagile Vx7531 Subscribe
Thinkagile Vx7531 Firmware Subscribe
Thinkagile Vx7820 Subscribe
Thinkagile Vx7820 Firmware Subscribe
Thinkagile Vx 1se Subscribe
Thinkagile Vx 1se Firmware Subscribe
Thinkagile Vx 2u4n Subscribe
Thinkagile Vx 2u4n Firmware Subscribe
Thinkagile Vx 4u Subscribe
Thinkagile Vx 4u Firmware Subscribe
Thinkedge Se450 Subscribe
Thinkedge Se450 Firmware Subscribe
Thinkstation P920 Subscribe
Thinkstation P920 Firmware Subscribe
Thinksystem Sd530 Subscribe
Thinksystem Sd530 Firmware Subscribe
Thinksystem Sd630 V2 Subscribe
Thinksystem Sd630 V2 Firmware Subscribe
Thinksystem Sd650 Subscribe
Thinksystem Sd650-n V2 Subscribe
Thinksystem Sd650-n V2 Firmware Subscribe
Thinksystem Sd650 Firmware Subscribe
Thinksystem Sd650 V2 Subscribe
Thinksystem Sd650 V2 Firmware Subscribe
Thinksystem Se350 Subscribe
Thinksystem Se350 Firmware Subscribe
Thinksystem Sn550 Subscribe
Thinksystem Sn550 Firmware Subscribe
Thinksystem Sn550 V2 Subscribe
Thinksystem Sn550 V2 Firmware Subscribe
Thinksystem Sn850 Subscribe
Thinksystem Sn850 Firmware Subscribe
Thinksystem Sr150 Subscribe
Thinksystem Sr150 Firmware Subscribe
Thinksystem Sr158 Subscribe
Thinksystem Sr158 Firmware Subscribe
Thinksystem Sr250 Subscribe
Thinksystem Sr250 Firmware Subscribe
Thinksystem Sr250 V2 Subscribe
Thinksystem Sr250 V2 Firmware Subscribe
Thinksystem Sr258 Subscribe
Thinksystem Sr258 Firmware Subscribe
Thinksystem Sr258 V2 Subscribe
Thinksystem Sr258 V2 Firmware Subscribe
Thinksystem Sr530 Subscribe
Thinksystem Sr530 Firmware Subscribe
Thinksystem Sr550 Subscribe
Thinksystem Sr550 Firmware Subscribe
Thinksystem Sr570 Subscribe
Thinksystem Sr570 Firmware Subscribe
Thinksystem Sr590 Subscribe
Thinksystem Sr590 Firmware Subscribe
Thinksystem Sr630 Subscribe
Thinksystem Sr630 Firmware Subscribe
Thinksystem Sr630 V2 Subscribe
Thinksystem Sr630 V2 Firmware Subscribe
Thinksystem Sr645 Subscribe
Thinksystem Sr645 Firmware Subscribe
Thinksystem Sr645 V3 Subscribe
Thinksystem Sr645 V3 Firmware Subscribe
Thinksystem Sr650 Subscribe
Thinksystem Sr650 Firmware Subscribe
Thinksystem Sr650 V2 Subscribe
Thinksystem Sr650 V2 Firmware Subscribe
Thinksystem Sr665 Subscribe
Thinksystem Sr665 Firmware Subscribe
Thinksystem Sr665 V3 Subscribe
Thinksystem Sr665 V3 Firmware Subscribe
Thinksystem Sr670 Subscribe
Thinksystem Sr670 Firmware Subscribe
Thinksystem Sr670 V2 Subscribe
Thinksystem Sr670 V2 Firmware Subscribe
Thinksystem Sr850 Subscribe
Thinksystem Sr850 Firmware Subscribe
Thinksystem Sr850 V2 Subscribe
Thinksystem Sr850 V2 Firmware Subscribe
Thinksystem Sr850p Subscribe
Thinksystem Sr850p Firmware Subscribe
Thinksystem Sr860 Subscribe
Thinksystem Sr860 Firmware Subscribe
Thinksystem Sr860 V2 Subscribe
Thinksystem Sr860 V2 Firmware Subscribe
Thinksystem Sr950 Subscribe
Thinksystem Sr950 Firmware Subscribe
Thinksystem St250 Subscribe
Thinksystem St250 Firmware Subscribe
Thinksystem St250 V2 Subscribe
Thinksystem St250 V2 Firmware Subscribe
Thinksystem St258 Subscribe
Thinksystem St258 Firmware Subscribe
Thinksystem St258 V2 Subscribe
Thinksystem St258 V2 Firmware Subscribe
Thinksystem St550 Subscribe
Thinksystem St550 Firmware Subscribe
Thinksystem St650 V2 Subscribe
Thinksystem St650 V2 Firmware Subscribe
Thinksystem St658 V2 Subscribe
Thinksystem St658 V2 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-32659 A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined.
Fixes

Solution

Customers should update to the version (or later) of Lenovo XClarity Controller (XCC) identified in the related Lenovo Product Security Advisory:  https://support.lenovo.com/us/en/product_security/LEN-118321 https://support.lenovo.com/us/en/product_security/LEN-118321


Workaround

No workaround given by the vendor.

History

Thu, 30 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2025-01-30T18:26:37.319Z

Reserved: 2023-03-30T12:46:45.646Z

Link: CVE-2023-29056

cve-icon Vulnrichment

Updated: 2024-08-02T14:00:14.660Z

cve-icon NVD

Status : Modified

Published: 2023-04-28T22:15:09.073

Modified: 2024-11-21T07:56:27.923

Link: CVE-2023-29056

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses