4.8

CVE-2019-6195

An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to higher-privileged information if 1) “LDAP Authentication Only with Local Authorization” mode is configured and used by XCC, and 2) a lesser privileged user logs into XCC within 1 minute of a higher privileged user logging out. The authorization bypass does not exist when “Local Authentication and Authorization” or “LDAP Authentication and Authorization” modes are configured and used by XCC.

Data is provided by the National Vulnerability Database (NVD)
LenovoXclarity Controller Version < 3.01_tei392o
   LenovoThinkagile Hx 1000 Version-
   LenovoThinkagile Hx 2000 Version-
   LenovoThinkagile Hx 3000 Version-
   LenovoThinkagile Hx 5000 Version-
   LenovoThinkagile Hx 7000 Version-
   LenovoThinkagile Vx 1000 Version-
   LenovoThinkagile Vx 2000 Version-
   LenovoThinkagile Vx 3000 Version-
   LenovoThinkagile Vx 5000 Version-
   LenovoThinkagile Vx 7000 Version-
   LenovoThinksystem Sd530 Version-
   LenovoThinksystem Sd650 Dwc Version-
   LenovoThinksystem Sn550 Version-
   LenovoThinksystem Sn850 Version-
   LenovoThinksystem Sr150 Version-
   LenovoThinksystem Sr158 Version-
   LenovoThinksystem Sr250 Version-
   LenovoThinksystem Sr258 Version-
   LenovoThinksystem Sr850 Version-
   LenovoThinksystem Sr860 Version-
   LenovoThinksystem St250 Version-
   LenovoThinksystem St258 Version-
LenovoXclarity Controller Version < 3.08_cdi340v
   LenovoThinkagile Hx 1000 Version-
   LenovoThinkagile Hx 2000 Version-
   LenovoThinkagile Hx 3000 Version-
   LenovoThinkagile Hx 5000 Version-
   LenovoThinkagile Hx 7000 Version-
   LenovoThinkagile Mx Sr650 Version-
   LenovoThinkagile Vx 1000 Version-
   LenovoThinkagile Vx 2000 Version-
   LenovoThinkagile Vx 3000 Version-
   LenovoThinkagile Vx 5000 Version-
   LenovoThinkagile Vx 7000 Version-
   LenovoThinksystem Sr530 Version-
   LenovoThinksystem Sr550 Version-
   LenovoThinksystem Sr570 Version-
   LenovoThinksystem Sr590 Version-
   LenovoThinksystem Sr630 Version-
   LenovoThinksystem Sr650 Version-
   LenovoThinksystem St550 Version-
   LenovoThinksystem St558 Version-
LenovoXclarity Controller Version < 1.71_psi328n
   LenovoThinksystem Sr950 Server Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.14% 0.353
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.8 1.2 3.6
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
nvd@nist.gov 2.1 3.9 2.9
AV:N/AC:H/Au:S/C:P/I:N/A:N
psirt@lenovo.com 4.8 1.2 3.6
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.