A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting XCC devices configured in LDAP Authentication Only Mode and using an LDAP server that supports “unauthenticated bind”, such as Microsoft Active Directory. An unauthenticated user can gain read-only access to XCC in such a configuration, thereby allowing the XCC device configuration to be viewed but not changed. XCC devices configured to use local authentication, LDAP Authentication + Authorization Mode, or LDAP servers that support only “authenticated bind” and/or “anonymous bind” are not affected.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NLenovo Thinkagile Hx1320
HWLenovoall versionsLenovo Thinkagile Hx1321
HWLenovoall versionsLenovo Thinkagile Hx1520 R
HWLenovoall versionsLenovo Thinkagile Hx1521 R
HWLenovoall versionsLenovo Thinkagile Hx2320 E
HWLenovoall versionsLenovo Thinkagile Hx2321
HWLenovoall versionsLenovo Thinkagile Hx3320
HWLenovoall versionsLenovo Thinkagile Hx3321
HWLenovoall versionsLenovo Thinkagile Hx3375
HWLenovoall versionsLenovo Thinkagile Hx3376
HWLenovoall versionsLenovo Thinkagile Hx3520 G
HWLenovoall versionsLenovo Thinkagile Hx3521 G
HWLenovoall versionsLenovo Thinkagile Hx5520
HWLenovoall versionsLenovo Thinkagile Hx5520 C
HWLenovoall versionsLenovo Thinkagile Hx5521
HWLenovoall versionsLenovo Thinkagile Hx5521 C
HWLenovoall versionsLenovo Thinkagile Hx7520
HWLenovoall versionsLenovo Thinkagile Hx7521
HWLenovoall versionsLenovo Thinkagile Hx7820
HWLenovoall versionsLenovo Thinkagile Hx7821
HWLenovoall versionsLenovo Thinkagile Mx1021
HWLenovoall versionsLenovo Thinkagile Vx2320
HWLenovoall versionsLenovo Thinkagile Vx3320
HWLenovoall versionsLenovo Thinkagile Vx3520 G
HWLenovoall versionsLenovo Thinkagile Vx5520
HWLenovoall versionsLenovo Thinkagile Vx7320 N
HWLenovoall versionsLenovo Thinkagile Vx7520
HWLenovoall versionsLenovo Thinkagile Vx7520 N
HWLenovoall versionsLenovo Thinkstation P920
HWLenovoall versionsLenovo Thinksystem Sd650
HWLenovoall versions
Related vulnerabilities
OpenSLP — uszkodzenie pamięci sterty umożliwiające RCE lub DoS
A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user w...
An authenticated XCC user can change permissions for any user through a crafted API command.
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted A...
A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically craf...