First published: Thu Jan 12 2017(Updated: )
Privilege Escalation in Lenovo XClarity Administrator earlier than 1.2.0, if LXCA is used to manage rack switches or chassis with embedded input/output modules (IOMs), certain log files viewable by authenticated users may contain passwords for internal administrative LXCA accounts with temporary passwords that are used internally by LXCA code.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo XClarity Administrator | <=1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8221 is classified as a high severity privilege escalation vulnerability.
To mitigate CVE-2016-8221, upgrade Lenovo XClarity Administrator to version 1.2.0 or later.
CVE-2016-8221 affects Lenovo XClarity Administrator versions prior to 1.2.0 managing rack switches or chassis with embedded I/O modules.
CVE-2016-8221 allows authenticated users to view sensitive log files that may expose passwords for internal administrative accounts.
As of now, the recommended solution for CVE-2016-8221 is to update to the fixed version, as workarounds may not fully mitigate the risk.