CVE-2021-3956
A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting XCC devices configured in LDAP Authentication Only Mode and using an LDAP server that supports “unauthenticated bind”, such as Microsoft Active Directory. An unauthenticated user can gain read-only access to XCC in such a configuration, thereby allowing the XCC device configuration to be viewed but not changed. XCC devices configured to use local authentication, LDAP Authentication + Authorization Mode, or LDAP servers that support only “authenticated bind” and/or “anonymous bind” are not affected.
Published:May 18, 2022
Last Modified:Nov 21, 2024
EPS:May 18, 2022
EPSS Score:0.00183
CVSS Score:4.3
Affected Products
Vendor
Product
Action
Vendor
Lenovo
Product
Thinkagile Hx1320
Lenovo
Thinkagile Hx1320
Vendor
Lenovo
Product
Thinkagile Hx1321
Lenovo
Thinkagile Hx1321
Vendor
Lenovo
Product
Thinkagile Hx1520-r
Lenovo
Thinkagile Hx1520-r
Vendor
Lenovo
Product
Thinkagile Hx1521-r
Lenovo
Thinkagile Hx1521-r
Vendor
Lenovo
Product
Thinkagile Hx2320-e
Lenovo
Thinkagile Hx2320-e
Vendor
Lenovo
Product
Thinkagile Hx2321
Lenovo
Thinkagile Hx2321
Vendor
Lenovo
Product
Thinkagile Hx3320
Lenovo
Thinkagile Hx3320
Vendor
Lenovo
Product
Thinkagile Hx3321
Lenovo
Thinkagile Hx3321
Vendor
Lenovo
Product
Thinkagile Hx3375
Lenovo
Thinkagile Hx3375
Vendor
Lenovo
Product
Thinkagile Hx3376
Lenovo
Thinkagile Hx3376
Vendor
Lenovo
Product
Thinkagile Hx3520-g
Lenovo
Thinkagile Hx3520-g
Vendor
Lenovo
Product
Thinkagile Hx3521-g
Lenovo
Thinkagile Hx3521-g
Vendor
Lenovo
Product
Thinkagile Hx5520
Lenovo
Thinkagile Hx5520
Vendor
Lenovo
Product
Thinkagile Hx5520-c
Lenovo
Thinkagile Hx5520-c
Vendor
Lenovo
Product
Thinkagile Hx5521
Lenovo
Thinkagile Hx5521
Vendor
Lenovo
Product
Thinkagile Hx5521-c
Lenovo
Thinkagile Hx5521-c
Vendor
Lenovo
Product
Thinkagile Hx7520
Lenovo
Thinkagile Hx7520
Vendor
Lenovo
Product
Thinkagile Hx7521
Lenovo
Thinkagile Hx7521
Vendor
Lenovo
Product
Thinkagile Hx7820
Lenovo
Thinkagile Hx7820
Vendor
Lenovo
Product
Thinkagile Hx7821
Lenovo
Thinkagile Hx7821
Vendor
Lenovo
Product
Thinkagile Mx1021
Lenovo
Thinkagile Mx1021
Vendor
Lenovo
Product
Thinkagile Vx2320
Lenovo
Thinkagile Vx2320
Vendor
Lenovo
Product
Thinkagile Vx3320
Lenovo
Thinkagile Vx3320
Vendor
Lenovo
Product
Thinkagile Vx3520-g
Lenovo
Thinkagile Vx3520-g
Vendor
Lenovo
Product
Thinkagile Vx5520
Lenovo
Thinkagile Vx5520
Vendor
Lenovo
Product
Thinkagile Vx7320 N
Lenovo
Thinkagile Vx7320 N
Vendor
Lenovo
Product
Thinkagile Vx7520
Lenovo
Thinkagile Vx7520
Vendor
Lenovo
Product
Thinkagile Vx7520 N
Lenovo
Thinkagile Vx7520 N
Vendor
Lenovo
Product
Thinkstation P920
Lenovo
Thinkstation P920
Vendor
Lenovo
Product
Thinksystem Sd650
Lenovo
Thinksystem Sd650
Vendor
Lenovo
Product
Thinksystem Se350
Lenovo
Thinksystem Se350
Vendor
Lenovo
Product
Thinksystem Sn550
Lenovo
Thinksystem Sn550
Vendor
Lenovo
Product
Thinksystem Sn850
Lenovo
Thinksystem Sn850
Vendor
Lenovo
Product
Thinksystem Sr530
Lenovo
Thinksystem Sr530
Vendor
Lenovo
Product
Thinksystem Sr550
Lenovo
Thinksystem Sr550
Vendor
Lenovo
Product
Thinksystem Sr570
Lenovo
Thinksystem Sr570
Vendor
Lenovo
Product
Thinksystem Sr590
Lenovo
Thinksystem Sr590
Vendor
Lenovo
Product
Thinksystem Sr630
Lenovo
Thinksystem Sr630
Vendor
Lenovo
Product
Thinksystem Sr645
Lenovo
Thinksystem Sr645
Vendor
Lenovo
Product
Thinksystem Sr650
Lenovo
Thinksystem Sr650
Vendor
Lenovo
Product
Thinksystem Sr665
Lenovo
Thinksystem Sr665
Vendor
Lenovo
Product
Thinksystem Sr850
Lenovo
Thinksystem Sr850
Vendor
Lenovo
Product
Thinksystem Sr860
Lenovo
Thinksystem Sr860
Vendor
Lenovo
Product
Thinksystem Sr950
Lenovo
Thinksystem Sr950
Vendor
Lenovo
Product
Thinksystem St550
Lenovo
Thinksystem St550
Vendor
Lenovo
Product
Xclarity Controller
Lenovo
Xclarity Controller
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
