4.9
CVE-2021-3473
- EPSS 0.1%
- Published 13.04.2021 21:15:25
- Last modified 21.11.2024 06:21:37
- Source psirt@lenovo.com
- Teams watchlist Login
- Open Login
An internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/restore password may be written to an internal XCC log buffer if Lenovo XClarity Administrator (LXCA) is used to perform the backup/restore. The backup/restore password typically exists in this internal log buffer for less than 10 minutes before being overwritten. Generating an FFDC service log will include the log buffer contents, including the backup/restore password if present. The FFDC service log is only generated when requested by a privileged XCC user and it is only accessible to the privileged XCC user that requested the file. The backup/restore password is not captured if the backup/restore is initiated directly from XCC.
Data is provided by the National Vulnerability Database (NVD)
Lenovo ≫ Xclarity Controller Version6.00_cdi370q
Lenovo ≫ Thinkagile Hx1320 Version-
Lenovo ≫ Thinkagile Hx2320 Version-
Lenovo ≫ Thinkagile Hx3320 Version-
Lenovo ≫ Thinkagile Hx3375 Version-
Lenovo ≫ Thinkagile Hx3520-g Version-
Lenovo ≫ Thinkagile Hx3720 Version-
Lenovo ≫ Thinkagile Hx5520 Version-
Lenovo ≫ Thinkagile Hx7520 Version-
Lenovo ≫ Thinkagile Hx7820 Version-
Lenovo ≫ Thinkagile Mx Certified Nodes Version-
Lenovo ≫ Thinkagile Vx 1u Version-
Lenovo ≫ Thinkagile Vx 2u Version-
Lenovo ≫ Thinkagile Vx Dense Version-
Lenovo ≫ Thinksystem Sr530 Version-
Lenovo ≫ Thinksystem Sr570 Version-
Lenovo ≫ Thinksystem Sr590 Version-
Lenovo ≫ Thinksystem Sr630 Version-
Lenovo ≫ Thinksystem Sr650 Version-
Lenovo ≫ Thinksystem St550 Version-
Lenovo ≫ Thinksystem St558 Version-
Lenovo ≫ Thinkagile Hx2320 Version-
Lenovo ≫ Thinkagile Hx3320 Version-
Lenovo ≫ Thinkagile Hx3375 Version-
Lenovo ≫ Thinkagile Hx3520-g Version-
Lenovo ≫ Thinkagile Hx3720 Version-
Lenovo ≫ Thinkagile Hx5520 Version-
Lenovo ≫ Thinkagile Hx7520 Version-
Lenovo ≫ Thinkagile Hx7820 Version-
Lenovo ≫ Thinkagile Mx Certified Nodes Version-
Lenovo ≫ Thinkagile Vx 1u Version-
Lenovo ≫ Thinkagile Vx 2u Version-
Lenovo ≫ Thinkagile Vx Dense Version-
Lenovo ≫ Thinksystem Sr530 Version-
Lenovo ≫ Thinksystem Sr570 Version-
Lenovo ≫ Thinksystem Sr590 Version-
Lenovo ≫ Thinksystem Sr630 Version-
Lenovo ≫ Thinksystem Sr650 Version-
Lenovo ≫ Thinksystem St550 Version-
Lenovo ≫ Thinksystem St558 Version-
Lenovo ≫ Xclarity Controller Version1.10_tgbt12q
Lenovo ≫ Thinkagile Hx1320 Version-
Lenovo ≫ Thinkagile Hx2320 Version-
Lenovo ≫ Thinkagile Hx3320 Version-
Lenovo ≫ Thinkagile Hx3375 Version-
Lenovo ≫ Thinkagile Hx3520-g Version-
Lenovo ≫ Thinkagile Hx3720 Version-
Lenovo ≫ Thinkagile Hx5520 Version-
Lenovo ≫ Thinkagile Hx7520 Version-
Lenovo ≫ Thinkagile Hx7820 Version-
Lenovo ≫ Thinkagile Mx Certified Nodes Version-
Lenovo ≫ Thinkagile Mx1020 Version-
Lenovo ≫ Thinkagile Vx 1u Version-
Lenovo ≫ Thinkagile Vx 2u Version-
Lenovo ≫ Thinkagile Vx Dense Version-
Lenovo ≫ Thinksystem Se350 Version-
Lenovo ≫ Thinksystem Sr670 Version-
Lenovo ≫ Thinksystem Sr850p Version-
Lenovo ≫ Thinkagile Hx2320 Version-
Lenovo ≫ Thinkagile Hx3320 Version-
Lenovo ≫ Thinkagile Hx3375 Version-
Lenovo ≫ Thinkagile Hx3520-g Version-
Lenovo ≫ Thinkagile Hx3720 Version-
Lenovo ≫ Thinkagile Hx5520 Version-
Lenovo ≫ Thinkagile Hx7520 Version-
Lenovo ≫ Thinkagile Hx7820 Version-
Lenovo ≫ Thinkagile Mx Certified Nodes Version-
Lenovo ≫ Thinkagile Mx1020 Version-
Lenovo ≫ Thinkagile Vx 1u Version-
Lenovo ≫ Thinkagile Vx 2u Version-
Lenovo ≫ Thinkagile Vx Dense Version-
Lenovo ≫ Thinksystem Se350 Version-
Lenovo ≫ Thinksystem Sr670 Version-
Lenovo ≫ Thinksystem Sr850p Version-
Lenovo ≫ Xclarity Controller Version2.14_psi338i
Lenovo ≫ Xclarity Controller Version4.40_tei3b2p
Lenovo ≫ Thinkagile Hx1320 Version-
Lenovo ≫ Thinkagile Hx2320 Version-
Lenovo ≫ Thinkagile Hx3320 Version-
Lenovo ≫ Thinkagile Hx3375 Version-
Lenovo ≫ Thinkagile Hx3520-g Version-
Lenovo ≫ Thinkagile Hx3720 Version-
Lenovo ≫ Thinkagile Hx5520 Version-
Lenovo ≫ Thinkagile Hx7520 Version-
Lenovo ≫ Thinkagile Hx7820 Version-
Lenovo ≫ Thinkagile Vx 1u Version-
Lenovo ≫ Thinkagile Vx 2u Version-
Lenovo ≫ Thinkagile Vx Dense Version-
Lenovo ≫ Thinksystem Sd530 Version-
Lenovo ≫ Thinksystem Sd650 Version-
Lenovo ≫ Thinksystem Sn550 Version-
Lenovo ≫ Thinksystem Sn850 Version-
Lenovo ≫ Thinksystem Sr150 Version-
Lenovo ≫ Thinksystem Sr158 Version-
Lenovo ≫ Thinksystem Sr250 Version-
Lenovo ≫ Thinksystem Sr258 Version-
Lenovo ≫ Thinksystem Sr850 Version-
Lenovo ≫ Thinksystem Sr860 Version-
Lenovo ≫ Thinksystem St250 Version-
Lenovo ≫ Thinksystem St258 Version-
Lenovo ≫ Thinkagile Hx2320 Version-
Lenovo ≫ Thinkagile Hx3320 Version-
Lenovo ≫ Thinkagile Hx3375 Version-
Lenovo ≫ Thinkagile Hx3520-g Version-
Lenovo ≫ Thinkagile Hx3720 Version-
Lenovo ≫ Thinkagile Hx5520 Version-
Lenovo ≫ Thinkagile Hx7520 Version-
Lenovo ≫ Thinkagile Hx7820 Version-
Lenovo ≫ Thinkagile Vx 1u Version-
Lenovo ≫ Thinkagile Vx 2u Version-
Lenovo ≫ Thinkagile Vx Dense Version-
Lenovo ≫ Thinksystem Sd530 Version-
Lenovo ≫ Thinksystem Sd650 Version-
Lenovo ≫ Thinksystem Sn550 Version-
Lenovo ≫ Thinksystem Sn850 Version-
Lenovo ≫ Thinksystem Sr150 Version-
Lenovo ≫ Thinksystem Sr158 Version-
Lenovo ≫ Thinksystem Sr250 Version-
Lenovo ≫ Thinksystem Sr258 Version-
Lenovo ≫ Thinksystem Sr850 Version-
Lenovo ≫ Thinksystem Sr860 Version-
Lenovo ≫ Thinksystem St250 Version-
Lenovo ≫ Thinksystem St258 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.1% | 0.248 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
psirt@lenovo.com | 4.5 | 0.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
|
CWE-312 Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.