Authorization Bypass in Lenovo XClarity Controller
CVE-2019-6195
4.8MEDIUM
What is CVE-2019-6195?
An authorization bypass vulnerability in Lenovo XClarity Controller allows a valid authenticated user with lesser privileges access to higher-privileged information under specific conditions. If configured to use 'LDAP Authentication Only with Local Authorization,' a lower-privileged user can gain read-only access to sensitive data if they log in shortly after a higher-privileged user logs out. The issue does not manifest under other authentication configurations, highlighting the importance of proper mode selection to protect sensitive information.
Affected Version(s)
XClarity Controller (XCC) < 3.08 CDI340V
XClarity Controller (XCC) < 3.01 TEI392O
XClarity Controller (XCC) < 1.71 PSI328N