CWE
863
Advisory Published
Updated

CVE-2021-3956

First published: Wed May 18 2022(Updated: )

A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting XCC devices configured in LDAP Authentication Only Mode and using an LDAP server that supports “unauthenticated bind”, such as Microsoft Active Directory. An unauthenticated user can gain read-only access to XCC in such a configuration, thereby allowing the XCC device configuration to be viewed but not changed. XCC devices configured to use local authentication, LDAP Authentication + Authorization Mode, or LDAP servers that support only “authenticated bind” and/or “anonymous bind” are not affected.

Credit: psirt@lenovo.com

Affected SoftwareAffected VersionHow to fix
Lenovo XClarity Controller<7.22_cdi382o
Lenovo ThinkAgile HX1320 Firmware
Lenovo ThinkAgile HX1321 Firmware
Lenovo ThinkAgile HX1520-R Firmware
Lenovo ThinkAgile HX1521-R Firmware
Lenovo ThinkAgile HX2320-E Firmware
Lenovo ThinkAgile HX2321
Lenovo ThinkAgile HX3320 Firmware
Lenovo ThinkAgile HX3321 Firmware
Lenovo ThinkAgile HX3375
Lenovo ThinkAgile HX3376 Firmware
Lenovo ThinkAgile HX3520-G
Lenovo ThinkAgile HX3521-G Firmware
Lenovo ThinkAgile HX5520-C
Lenovo ThinkAgile HX5520
Lenovo ThinkAgile HX5521 Firmware
Lenovo ThinkAgile HX5521
Lenovo ThinkAgile HX7520
Lenovo ThinkAgile HX7521 Firmware
Lenovo ThinkAgile Vx2320 Firmware
Lenovo ThinkAgile Vx3320 Firmware
Lenovo ThinkAgile Vx3520-G Firmware
Lenovo ThinkAgile VX5520 Firmware
Lenovo ThinkAgile VX7320 N
Lenovo ThinkAgile VX7520
Lenovo ThinkAgile VX7520
Lenovo ThinkStation P920
Lenovo ThinkSystem SR530
Lenovo ThinkSystem SR550
Lenovo ThinkSystem SR570
Lenovo ThinkSystem SR590
Lenovo ThinkSystem SR630 Firmware
Lenovo ThinkSystem SR645 Firmware
Lenovo ThinkSystem SR650 V2
Lenovo ThinkSystem SR665
Lenovo ThinkSystem ST550 Firmware
Lenovo XClarity Controller<2.32_psi342n
Lenovo ThinkAgile HX7820 Firmware
Lenovo ThinkAgile HX7821
Lenovo ThinkSystem SR950 Firmware
Lenovo XClarity Controller<3.41_tei382m
Lenovo ThinkAgile MX1021 on SE350
Lenovo ThinkSystem SE350
Lenovo XClarity Controller<4.83_tei3c0n
Lenovo ThinkSystem SD650
Lenovo ThinkSystem SN550 Firmware
Lenovo ThinkSystem SN850
Lenovo ThinkSystem SR850P
Lenovo ThinkSystem SR860 Firmware
Lenovo XClarity Controller<1.51_tgbt24l
Lenovo ThinkSystem SR850P=2.0
Lenovo ThinkSystem SR860 Firmware=2.0

Remedy

Update to the Lenovo XClarity Controller (XCC) version (or higher) as recommended in the Product Impact section of LEN-72074.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2021-3956?

    CVE-2021-3956 is a read-only authentication bypass vulnerability in Lenovo XClarity Controller (XCC) firmware.

  • Which devices are affected by CVE-2021-3956?

    The Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware is affected by CVE-2021-3956.

  • What is the severity level of CVE-2021-3956?

    CVE-2021-3956 has a severity level of 5.3 (medium).

  • How does CVE-2021-3956 affect LDAP Authentication Only Mode?

    CVE-2021-3956 affects XCC devices configured in LDAP Authentication Only Mode and using an LDAP server that supports 'unauthenticated bind', such as Microsoft Active Directory.

  • How can I fix CVE-2021-3956?

    To fix CVE-2021-3956, Lenovo has released a firmware update. Please refer to the official Lenovo security advisory for more information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203