CVE-2019-6195 Details
Description
An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to higher-privileged information if 1) “LDAP Authentication Only with Local Authorization” mode is configured and used by XCC, and 2) a lesser privileged user logs into XCC within 1 minute of a higher privileged user logging out. The authorization bypass does not exist when “Local Authentication and Authorization” or “LDAP Authentication and Authorization” modes are configured and used by XCC.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-29116 | CVE | Vendor Advisory |
| https://support.lenovo.com/us/en/product_security/LEN-29116 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
| CWE-264 | Permissions, Privileges, and Access Controls | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lenovo xclarity controller | < 3.01_tei392o < 3.08_cdi340v < 1.71_psi328n |
CPE
Remediation
| |
| lenovo thinkagile hx 1000 | All versions |
CPE
Remediation
| |
| lenovo thinkagile hx 2000 | All versions |
CPE
Remediation
| |
| lenovo thinkagile hx 3000 | All versions |
CPE
Remediation
| |
| lenovo thinkagile hx 5000 | All versions |
CPE
Remediation
| |
| lenovo thinkagile hx 7000 | All versions |
CPE
Remediation
| |
| lenovo thinkagile vx 1000 | All versions |
CPE
Remediation
| |
| lenovo thinkagile vx 2000 | All versions |
CPE
Remediation
| |
| lenovo thinkagile vx 3000 | All versions |
CPE
Remediation
| |
| lenovo thinkagile vx 5000 | All versions |
CPE
Remediation
| |
| lenovo thinkagile vx 7000 | All versions |
CPE
Remediation
| |
| lenovo thinksystem sd530 | All versions |
CPE
Remediation
| |
| lenovo thinksystem sd650 dwc | All versions |
CPE
Remediation
| |
| lenovo thinksystem sn550 | All versions |
CPE
Remediation
| |
| lenovo thinksystem sn850 | All versions |
CPE
Remediation
| |
| lenovo thinksystem sr150 | All versions |
CPE
Remediation
| |
| lenovo thinksystem sr158 | All versions |
CPE
Remediation
| |
| lenovo thinksystem sr250 | All versions |
CPE
Remediation
| |
| lenovo thinksystem sr258 | All versions |
CPE
Remediation
| |
| lenovo thinksystem sr850 | All versions |
CPE
Remediation
| |
| lenovo thinksystem sr860 | All versions |
CPE
Remediation
| |
| lenovo thinksystem st250 | All versions |
CPE
Remediation
| |
| lenovo thinksystem st258 | All versions |
CPE
Remediation
| |
| lenovo thinkagile mx sr650 | All versions |
CPE
Remediation
| |
| lenovo thinksystem sr530 | All versions |
CPE
Remediation
| |
| lenovo thinksystem sr550 | All versions |
CPE
Remediation
| |
| lenovo thinksystem sr570 | All versions |
CPE
Remediation
| |
| lenovo thinksystem sr590 | All versions |
CPE
Remediation
| |
| lenovo thinksystem sr630 | All versions |
CPE
Remediation
| |
| lenovo thinksystem sr650 | All versions |
CPE
Remediation
| |
| lenovo thinksystem st550 | All versions |
CPE
Remediation
| |
| lenovo thinksystem st558 | All versions |
CPE
Remediation
| |
| lenovo thinksystem sr950 server | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Mar 4, 2020 | Initial Analysis | [email protected] |
| Feb 14, 2020 | CVE Modified | [email protected] |