CVE Feed

    Dashboard / CVE / CVE-2019-6195

    CVE-2019-6195

    An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to higher-privileged information if 1) “LDAP Authentication Only with Local Authorization” mode is configured and used by XCC, and 2) a lesser privileged user logs into XCC within 1 minute of a higher privileged user logging out. The authorization bypass does not exist when “Local Authentication and Authorization” or “LDAP Authentication and Authorization” modes are configured and used by XCC.

    Published:Feb 14, 2020
    Last Modified:Nov 21, 2024
    EPS:Feb 14, 2020
    EPSS Score:0.00144
    CVSS Score:4.8

    Affected Products

    Vendor
    Lenovo
    Product
    Thinkagile Hx 1000
    Vendor
    Lenovo
    Product
    Thinkagile Hx 2000
    Vendor
    Lenovo
    Product
    Thinkagile Hx 3000
    Vendor
    Lenovo
    Product
    Thinkagile Hx 5000
    Vendor
    Lenovo
    Product
    Thinkagile Hx 7000
    Vendor
    Lenovo
    Product
    Thinkagile Mx Sr650
    Vendor
    Lenovo
    Product
    Thinkagile Vx 1000
    Vendor
    Lenovo
    Product
    Thinkagile Vx 2000
    Vendor
    Lenovo
    Product
    Thinkagile Vx 3000
    Vendor
    Lenovo
    Product
    Thinkagile Vx 5000
    Vendor
    Lenovo
    Product
    Thinkagile Vx 7000
    Vendor
    Lenovo
    Product
    Thinksystem Sd530
    Vendor
    Lenovo
    Product
    Thinksystem Sd650 Dwc
    Vendor
    Lenovo
    Product
    Thinksystem Sn550
    Vendor
    Lenovo
    Product
    Thinksystem Sn850
    Vendor
    Lenovo
    Product
    Thinksystem Sr150
    Vendor
    Lenovo
    Product
    Thinksystem Sr158
    Vendor
    Lenovo
    Product
    Thinksystem Sr250
    Vendor
    Lenovo
    Product
    Thinksystem Sr258
    Vendor
    Lenovo
    Product
    Thinksystem Sr530
    Vendor
    Lenovo
    Product
    Thinksystem Sr550
    Vendor
    Lenovo
    Product
    Thinksystem Sr570
    Vendor
    Lenovo
    Product
    Thinksystem Sr590
    Vendor
    Lenovo
    Product
    Thinksystem Sr630
    Vendor
    Lenovo
    Product
    Thinksystem Sr650
    Vendor
    Lenovo
    Product
    Thinksystem Sr850
    Vendor
    Lenovo
    Product
    Thinksystem Sr860
    Vendor
    Lenovo
    Product
    Thinksystem Sr950 Server
    Vendor
    Lenovo
    Product
    Thinksystem St250
    Vendor
    Lenovo
    Product
    Thinksystem St258
    Vendor
    Lenovo
    Product
    Thinksystem St550
    Vendor
    Lenovo
    Product
    Thinksystem St558
    Vendor
    Lenovo
    Product
    Xclarity Controller

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High