5.3

CVE-2021-3956

A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting XCC devices configured in LDAP Authentication Only Mode and using an LDAP server that supports “unauthenticated bind”, such as Microsoft Active Directory. An unauthenticated user can gain read-only access to XCC in such a configuration, thereby allowing the XCC device configuration to be viewed but not changed. XCC devices configured to use local authentication, LDAP Authentication + Authorization Mode, or LDAP servers that support only “authenticated bind” and/or “anonymous bind” are not affected.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LenovoXclarity Controller Version < 7.22_cdi382o
   LenovoThinkagile Hx1320 Version-
   LenovoThinkagile Hx1321 Version-
   LenovoThinkagile Hx1520-r Version-
   LenovoThinkagile Hx1521-r Version-
   LenovoThinkagile Hx2320-e Version-
   LenovoThinkagile Hx2321 Version-
   LenovoThinkagile Hx3320 Version-
   LenovoThinkagile Hx3321 Version-
   LenovoThinkagile Hx3375 Version-
   LenovoThinkagile Hx3376 Version-
   LenovoThinkagile Hx3520-g Version-
   LenovoThinkagile Hx3521-g Version-
   LenovoThinkagile Hx5520 Version-
   LenovoThinkagile Hx5520-c Version-
   LenovoThinkagile Hx5521 Version-
   LenovoThinkagile Hx5521-c Version-
   LenovoThinkagile Hx7520 Version-
   LenovoThinkagile Hx7521 Version-
   LenovoThinkagile Vx2320 Version-
   LenovoThinkagile Vx3320 Version-
   LenovoThinkagile Vx3520-g Version-
   LenovoThinkagile Vx5520 Version-
   LenovoThinkagile Vx7320 N Version-
   LenovoThinkagile Vx7520 Version-
   LenovoThinkagile Vx7520 N Version-
   LenovoThinkstation P920 Version-
   LenovoThinksystem Sr530 Version-
   LenovoThinksystem Sr550 Version-
   LenovoThinksystem Sr570 Version-
   LenovoThinksystem Sr590 Version-
   LenovoThinksystem Sr630 Version-
   LenovoThinksystem Sr645 Version-
   LenovoThinksystem Sr650 Version-
   LenovoThinksystem Sr665 Version-
   LenovoThinksystem St550 Version-
LenovoXclarity Controller Version < 2.32_psi342n
   LenovoThinkagile Hx7820 Version-
   LenovoThinkagile Hx7821 Version-
   LenovoThinksystem Sr950 Version-
LenovoXclarity Controller Version < 3.41_tei382m
   LenovoThinkagile Mx1021 Version-
   LenovoThinksystem Se350 Version-
LenovoXclarity Controller Version < 4.83_tei3c0n
   LenovoThinksystem Sd650 Version-
   LenovoThinksystem Sn550 Version-
   LenovoThinksystem Sn850 Version-
   LenovoThinksystem Sr850 Version-
   LenovoThinksystem Sr860 Version-
LenovoXclarity Controller Version < 1.51_tgbt24l
   LenovoThinksystem Sr850 Version2.0
   LenovoThinksystem Sr860 Version2.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.403
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
psirt@lenovo.com 4.3 2.8 1.4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.