CVE-2019-6195
An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to higher-privileged information if 1) “LDAP Authentication Only with Local Authorization” mode is configured and used by XCC, and 2) a lesser privileged user logs into XCC within 1 minute of a higher privileged user logging out. The authorization bypass does not exist when “Local Authentication and Authorization” or “LDAP Authentication and Authorization” modes are configured and used by XCC.
Published:Feb 14, 2020
Last Modified:Nov 21, 2024
EPS:Feb 14, 2020
EPSS Score:0.00144
CVSS Score:4.8
Affected Products
Vendor
Product
Action
Vendor
Lenovo
Product
Thinkagile Hx 1000
Lenovo
Thinkagile Hx 1000
Vendor
Lenovo
Product
Thinkagile Hx 2000
Lenovo
Thinkagile Hx 2000
Vendor
Lenovo
Product
Thinkagile Hx 3000
Lenovo
Thinkagile Hx 3000
Vendor
Lenovo
Product
Thinkagile Hx 5000
Lenovo
Thinkagile Hx 5000
Vendor
Lenovo
Product
Thinkagile Hx 7000
Lenovo
Thinkagile Hx 7000
Vendor
Lenovo
Product
Thinkagile Mx Sr650
Lenovo
Thinkagile Mx Sr650
Vendor
Lenovo
Product
Thinkagile Vx 1000
Lenovo
Thinkagile Vx 1000
Vendor
Lenovo
Product
Thinkagile Vx 2000
Lenovo
Thinkagile Vx 2000
Vendor
Lenovo
Product
Thinkagile Vx 3000
Lenovo
Thinkagile Vx 3000
Vendor
Lenovo
Product
Thinkagile Vx 5000
Lenovo
Thinkagile Vx 5000
Vendor
Lenovo
Product
Thinkagile Vx 7000
Lenovo
Thinkagile Vx 7000
Vendor
Lenovo
Product
Thinksystem Sd530
Lenovo
Thinksystem Sd530
Vendor
Lenovo
Product
Thinksystem Sd650 Dwc
Lenovo
Thinksystem Sd650 Dwc
Vendor
Lenovo
Product
Thinksystem Sn550
Lenovo
Thinksystem Sn550
Vendor
Lenovo
Product
Thinksystem Sn850
Lenovo
Thinksystem Sn850
Vendor
Lenovo
Product
Thinksystem Sr150
Lenovo
Thinksystem Sr150
Vendor
Lenovo
Product
Thinksystem Sr158
Lenovo
Thinksystem Sr158
Vendor
Lenovo
Product
Thinksystem Sr250
Lenovo
Thinksystem Sr250
Vendor
Lenovo
Product
Thinksystem Sr258
Lenovo
Thinksystem Sr258
Vendor
Lenovo
Product
Thinksystem Sr530
Lenovo
Thinksystem Sr530
Vendor
Lenovo
Product
Thinksystem Sr550
Lenovo
Thinksystem Sr550
Vendor
Lenovo
Product
Thinksystem Sr570
Lenovo
Thinksystem Sr570
Vendor
Lenovo
Product
Thinksystem Sr590
Lenovo
Thinksystem Sr590
Vendor
Lenovo
Product
Thinksystem Sr630
Lenovo
Thinksystem Sr630
Vendor
Lenovo
Product
Thinksystem Sr650
Lenovo
Thinksystem Sr650
Vendor
Lenovo
Product
Thinksystem Sr850
Lenovo
Thinksystem Sr850
Vendor
Lenovo
Product
Thinksystem Sr860
Lenovo
Thinksystem Sr860
Vendor
Lenovo
Product
Thinksystem Sr950 Server
Lenovo
Thinksystem Sr950 Server
Vendor
Lenovo
Product
Thinksystem St250
Lenovo
Thinksystem St250
Vendor
Lenovo
Product
Thinksystem St258
Lenovo
Thinksystem St258
Vendor
Lenovo
Product
Thinksystem St550
Lenovo
Thinksystem St550
Vendor
Lenovo
Product
Thinksystem St558
Lenovo
Thinksystem St558
Vendor
Lenovo
Product
Xclarity Controller
Lenovo
Xclarity Controller
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
