6.5

CVE-2019-6187

A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo ≫ Xclarity Controller Version < tei392m
   Lenovo ≫ Thinkagile 7x82 Version -
   Lenovo ≫ Thinkagile 7y11 Version -
   Lenovo ≫ Thinkagile 7y12 Version -
   Lenovo ≫ Thinkagile 7y88 Version -
   Lenovo ≫ Thinkagile 7y92 Version -
   Lenovo ≫ Thinkagile 7z03 Version -
   Lenovo ≫ Thinksystem Sd530 Version -
   Lenovo ≫ Thinksystem Sd650 Version -
   Lenovo ≫ Thinksystem Sn550 Version -
   Lenovo ≫ Thinksystem Sn850 Version -
   Lenovo ≫ Thinksystem Sr150 Version -
   Lenovo ≫ Thinksystem Sr158 Version -
   Lenovo ≫ Thinksystem Sr250 Version -
   Lenovo ≫ Thinksystem Sr258 Version -
   Lenovo ≫ Thinksystem Sr850 Version -
   Lenovo ≫ Thinksystem Sr860 Version -
   Lenovo ≫ Thinksystem St250 Version -
   Lenovo ≫ Thinksystem St258 Version -
Lenovo ≫ Xclarity Controller Version < cdi340m
   Lenovo ≫ Thinkagile 7d1h Version -
   Lenovo ≫ Thinkagile 7x83 Version -
   Lenovo ≫ Thinkagile 7y13 Version -
   Lenovo ≫ Thinkagile 7y14 Version -
   Lenovo ≫ Thinkagile 7y90 Version -
   Lenovo ≫ Thinkagile 7y93 Version -
   Lenovo ≫ Thinkagile 7y94 Version -
   Lenovo ≫ Thinkagile 7z04 Version -
   Lenovo ≫ Thinkagile 7z05 Version -
   Lenovo ≫ Thinkagile 7z06 Version -
   Lenovo ≫ Thinkagile 7z07 Version -
   Lenovo ≫ Thinkagile 7z20 Version -
   Lenovo ≫ Thinkagile Yx84 Version -
   Lenovo ≫ Thinksystem Sr530 Version -
   Lenovo ≫ Thinksystem Sr550 Version -
   Lenovo ≫ Thinksystem Sr570 Version -
   Lenovo ≫ Thinksystem Sr590 Version -
   Lenovo ≫ Thinksystem Sr630 Version -
   Lenovo ≫ Thinksystem Sr650 Version -
   Lenovo ≫ Thinksystem St550 Version -
   Lenovo ≫ Thinksystem St558 Version -
Lenovo ≫ Xclarity Controller Version < g1i312
   Lenovo ≫ Thinksystem Sr670 Version -
Lenovo ≫ Xclarity Controller Version < psi328m
   Lenovo ≫ Thinksystem Sr950 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.86% 0.537
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-1236 Improper Neutralization of Formula Elements in a CSV File

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

https://support.lenovo.com/solutions/LEN-29118
Patch
Vendor Advisory