CVE Feed

    Dashboard / CVE / CVE-2021-3473

    CVE-2021-3473

    An internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/restore password may be written to an internal XCC log buffer if Lenovo XClarity Administrator (LXCA) is used to perform the backup/restore. The backup/restore password typically exists in this internal log buffer for less than 10 minutes before being overwritten. Generating an FFDC service log will include the log buffer contents, including the backup/restore password if present. The FFDC service log is only generated when requested by a privileged XCC user and it is only accessible to the privileged XCC user that requested the file. The backup/restore password is not captured if the backup/restore is initiated directly from XCC.

    Published:Apr 13, 2021
    Last Modified:Nov 21, 2024
    EPS:Apr 13, 2021
    EPSS Score:0.001
    CVSS Score:4.5

    Affected Products

    Vendor
    Lenovo
    Product
    Thinkagile Hx1320
    Vendor
    Lenovo
    Product
    Thinkagile Hx2320
    Vendor
    Lenovo
    Product
    Thinkagile Hx3320
    Vendor
    Lenovo
    Product
    Thinkagile Hx3375
    Vendor
    Lenovo
    Product
    Thinkagile Hx3520-g
    Vendor
    Lenovo
    Product
    Thinkagile Hx3720
    Vendor
    Lenovo
    Product
    Thinkagile Hx5520
    Vendor
    Lenovo
    Product
    Thinkagile Hx7520
    Vendor
    Lenovo
    Product
    Thinkagile Hx7820
    Vendor
    Lenovo
    Product
    Thinkagile Mx1020
    Vendor
    Lenovo
    Product
    Thinkagile Mx Certified Nodes
    Vendor
    Lenovo
    Product
    Thinkagile Vx 1u
    Vendor
    Lenovo
    Product
    Thinkagile Vx 2u
    Vendor
    Lenovo
    Product
    Thinkagile Vx Dense
    Vendor
    Lenovo
    Product
    Thinksystem Sd530
    Vendor
    Lenovo
    Product
    Thinksystem Sd650
    Vendor
    Lenovo
    Product
    Thinksystem Se350
    Vendor
    Lenovo
    Product
    Thinksystem Sn550
    Vendor
    Lenovo
    Product
    Thinksystem Sn850
    Vendor
    Lenovo
    Product
    Thinksystem Sr150
    Vendor
    Lenovo
    Product
    Thinksystem Sr158
    Vendor
    Lenovo
    Product
    Thinksystem Sr250
    Vendor
    Lenovo
    Product
    Thinksystem Sr258
    Vendor
    Lenovo
    Product
    Thinksystem Sr530
    Vendor
    Lenovo
    Product
    Thinksystem Sr570
    Vendor
    Lenovo
    Product
    Thinksystem Sr590
    Vendor
    Lenovo
    Product
    Thinksystem Sr630
    Vendor
    Lenovo
    Product
    Thinksystem Sr650
    Vendor
    Lenovo
    Product
    Thinksystem Sr670
    Vendor
    Lenovo
    Product
    Thinksystem Sr850
    Vendor
    Lenovo
    Product
    Thinksystem Sr850p
    Vendor
    Lenovo
    Product
    Thinksystem Sr860
    Vendor
    Lenovo
    Product
    Thinksystem Sr950
    Vendor
    Lenovo
    Product
    Thinksystem St250
    Vendor
    Lenovo
    Product
    Thinksystem St258
    Vendor
    Lenovo
    Product
    Thinksystem St550
    Vendor
    Lenovo
    Product
    Thinksystem St558
    Vendor
    Lenovo
    Product
    Xclarity Controller

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High