CVE-2019-6195: Medium severity lenovo xclarity controller vulnerability
An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to higher-privileged information if 1) “LDAP Authentication Only with Local Authorization” mode is configured and used by XCC, and 2) a lesser privileged user logs into XCC within 1 minute of a higher privileged user logging out. The authorization bypass does not exist when “Local Authentication and Authorization” or “LDAP Authentication and Authorization” modes are configured and used by XCC.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6195?
The severity of CVE-2019-6195 is medium, with a severity value of 4.8.
How can I fix CVE-2019-6195?
To fix CVE-2019-6195, update Lenovo XClarity Controller (XCC) to version 3.08 CDI340V or later.
Which versions of Lenovo XClarity Controller are affected by CVE-2019-6195?
Lenovo XClarity Controller versions prior to 3.08 CDI340V, 3.01 TEI392O, and 1.71 PSI328N are affected by CVE-2019-6195.
What is the CWE number for CVE-2019-6195?
The CWE number for CVE-2019-6195 is CWE-269 and CWE-264.
Where can I find more information about CVE-2019-6195?
You can find more information about CVE-2019-6195 on the Lenovo product security website.