CVE-2019-6195

MEDIUM

Lenovo XClarity Controller < 3.01_tei392o - Privilege Escalation via LDAP Local Authorization Mode

Title source: llm
STIX 2.1

Description

An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to higher-privileged information if 1) “LDAP Authentication Only with Local Authorization” mode is configured and used by XCC, and 2) a lesser privileged user logs into XCC within 1 minute of a higher privileged user logging out. The authorization bypass does not exist when “Local Authentication and Authorization” or “LDAP Authentication and Authorization” modes are configured and used by XCC.

References (1)

Core 1
Core References

Scores

CVSS v3 4.8
EPSS 0.0014
EPSS Percentile 33.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-269 CWE-264
Status published
Products (1)
lenovo/xclarity_controller < 3.01_tei392o
Published Feb 14, 2020
Tracked Since Feb 18, 2026