CVE-2017-3764

MEDIUM

Lenovo XClarity Administrator <1.4.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated users with access to the LXCA web user interface. No password information of the user accounts is exposed.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
https://support.lenovo.com/us/en/product_security/LEN-16335

Scores

CVSS v3 5.3
EPSS 0.0073
EPSS Percentile 73.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
lenovo/xclarity_administrator < 1.4.0
Lenovo Group Ltd./xClarity Administrator Earlier than 1.4.0
Published Nov 30, 2017
Tracked Since Feb 18, 2026