CVE-2017-3745

Severity
7.8HIGH
EPSS
0.1%
top 73.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 20
Latest updateMay 17

Description

In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to password information for users that have previously authenticated to the LXCA's internal LDAP server, including administrative accounts and service accounts with administrative privileges. This is an issue only for users who have used local authentication with LXCA and not remote authentication against external LDAP or ADFS servers.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-h6cc-cf9q-cgxh: In Lenovo XClarity Administrator (LXCA) before 12022-05-17
CVEList
CVE-2017-3745: In Lenovo XClarity Administrator (LXCA) before 12017-06-20
CVE-2017-3745 (HIGH CVSS 7.8) | In Lenovo XClarity Administrator (L | cvebase.io