User Account Information Exposure in Lenovo XClarity Administrator
CVE-2017-3764

5.3MEDIUM

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
30 November 2017

Summary

A security flaw has been detected in Lenovo XClarity Administrator (LXCA) versions prior to 1.4.0. This vulnerability can lead to the exposure of LXCA user account names to unauthenticated users who have access to the LXCA web user interface. Importantly, while user account names may be visible, no password information is disclosed, reducing the scope of potential misuse. This issue highlights the importance of securing web interfaces to prevent unauthorized access to sensitive user data.

Affected Version(s)

xClarity Administrator Earlier than 1.4.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.