First published: Fri Feb 14 2020(Updated: )
An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to higher-privileged information if 1) “LDAP Authentication Only with Local Authorization” mode is configured and used by XCC, and 2) a lesser privileged user logs into XCC within 1 minute of a higher privileged user logging out. The authorization bypass does not exist when “Local Authentication and Authorization” or “LDAP Authentication and Authorization” modes are configured and used by XCC.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo XClarity Controller | <3.01_tei392o | |
Lenovo ThinkAgile HX1000 | ||
Lenovo ThinkAgile HX 2000 | ||
Lenovo ThinkAgile HX 3000 | ||
Lenovo ThinkAgile HX 5000 | ||
Lenovo Thinkagile Hx 7000 | ||
Lenovo ThinkAgile VX 1000 | ||
Lenovo ThinkAgile VX 2000 | ||
Lenovo ThinkAgile VX 3000 | ||
Lenovo ThinkAgile VX 5000 | ||
Lenovo ThinkAgile VX 7000 | ||
lenovo thinksystem sd530 | ||
lenovo thinksystem sd650 dwc | ||
Lenovo thinksystem sn550 | ||
Lenovo thinksystem sn850 | ||
lenovo thinksystem sr150 | ||
lenovo thinksystem sr158 | ||
lenovo thinksystem sr250 | ||
lenovo thinksystem sr258 | ||
Lenovo thinksystem sr850 | ||
Lenovo thinksystem sr860 | ||
lenovo thinksystem st250 | ||
lenovo thinksystem st258 | ||
Lenovo XClarity Controller | <3.08_cdi340v | |
Lenovo ThinkAgile MX SR650 | ||
Lenovo thinksystem sr530 | ||
Lenovo thinksystem sr550 | ||
Lenovo thinksystem sr570 | ||
Lenovo thinksystem sr590 | ||
Lenovo ThinkSystem SR630 Firmware | ||
Lenovo thinksystem sr650 | ||
Lenovo thinksystem st550 | ||
Lenovo thinksystem st558 | ||
Lenovo XClarity Controller | <1.71_psi328n | |
Lenovo ThinkSystem SR950 Server |
Update to Lenovo XClarity Controller (XCC) version 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-6195 is medium, with a severity value of 4.8.
To fix CVE-2019-6195, update Lenovo XClarity Controller (XCC) to version 3.08 CDI340V or later.
Lenovo XClarity Controller versions prior to 3.08 CDI340V, 3.01 TEI392O, and 1.71 PSI328N are affected by CVE-2019-6195.
The CWE number for CVE-2019-6195 is CWE-269 and CWE-264.
You can find more information about CVE-2019-6195 on the Lenovo product security website.