Description


A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined.

Related CPE's




o

lenovo

thinkagile_hx7530_firmware

2

h

lenovo

thinkagile_hx7530

2





















o

lenovo

thinkagile_hx2330_firmware

2












o

lenovo

thinkagile_hx3331_firmware

2

h

lenovo

thinkagile_hx3331

2



























o

lenovo

thinkagile_hx7531_firmware

2

h

lenovo

thinkagile_hx7531

2
























































































































































Weaknesses



NVD-CWE-noinfo


CWE-269

CVSS impact metrics


CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

5.9 · Medium

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2023-04-28T22:15:09.073

2 years ago

Last modified

2023-05-08T18:02:21.357

2 years ago