Sensitive Information Exposure in Lenovo XClarity Controller
CVE-2021-3473
What is CVE-2021-3473?
An internal security audit revealed that using Lenovo XClarity Administrator to perform a backup or restore on the Lenovo XClarity Controller can lead to the exposure of configuration backup/restore passwords. These sensitive credentials are temporarily stored in an internal log buffer, which may be included in FFDC service logs generated by a privileged user. Although the log contents are overwritten within approximately ten minutes, the risk remains for users who have access to these logs, as the backup/restore password may be inadvertently disclosed during log generation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
XClarity Controller (XCC) < 6.00 CDI370Q
XClarity Controller (XCC) < 1.10 TGBT12Q
XClarity Controller (XCC) < 3.20 TEI378W
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved