CVE-2019-6195

Severity
4.8MEDIUM
EPSS
0.1%
top 65.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14
Latest updateMay 24

Description

An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to higher-privileged information if 1) “LDAP Authentication Only with Local Authorization” mode is configured and used by XCC, and 2) a lesser privileged user logs into XCC within 1 minute of a higher privileged user logging out. The authorization bypass does not exist when “Local Auth

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages2 packages

NVDlenovo/xclarity_controller< 3.01_tei392o+2
CVEListV5lenovo/xclarity_controller_(xcc)unspecified3.08 CDI340V+2

🔴Vulnerability Details

2
GHSA
GHSA-xhgx-q9xg-fg3q: An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 32022-05-24
CVEList
CVE-2019-6195: An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 32020-02-14