An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to higher-privileged information if 1) “LDAP Authentication Only with Local Authorization” mode is configured and used by XCC, and 2) a lesser privileged user logs into XCC within 1 minute of a higher privileged user logging out. The authorization bypass does not exist when “Local Authentication and Authorization” or “LDAP Authentication and Authorization” modes are configured and used by XCC.
References
Link | Resource |
---|---|
https://support.lenovo.com/us/en/product_security/LEN-29116 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Information
Published : 2020-02-14 09:15
Updated : 2020-03-04 10:26
NVD link : CVE-2019-6195
Mitre link : CVE-2019-6195
JSON object : View
CWE
CWE-269
Improper Privilege Management
Products Affected
lenovo
- thinksystem_st558
- thinkagile_mx_sr650
- thinksystem_sr530
- thinksystem_sn550
- thinkagile_hx_1000
- thinkagile_hx_2000
- thinksystem_sd650_dwc
- thinkagile_vx_5000
- thinksystem_sd530
- thinksystem_st550
- thinksystem_sr630
- thinksystem_sr950_server
- thinkagile_hx_3000
- thinkagile_vx_7000
- thinkagile_vx_1000
- thinksystem_sr258
- thinkagile_hx_7000
- thinksystem_sn850
- thinksystem_sr590
- thinksystem_sr250
- thinksystem_sr550
- thinksystem_sr650
- thinkagile_vx_3000
- thinksystem_sr150
- xclarity_controller
- thinksystem_sr570
- thinkagile_vx_2000
- thinksystem_sr860
- thinksystem_st250
- thinkagile_hx_5000
- thinksystem_sr158
- thinksystem_st258
- thinksystem_sr850