Description
In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file system user may be able to retrieve a credential store containing the service processor user names and passwords for servers previously managed by that LXCA instance, and potentially decrypt those credentials more easily than intended.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-20668 | In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file system user may be able to retrieve a credential store containing the service processor user names and passwords for servers previously managed by that LXCA instance, and potentially decrypt those credentials more easily than intended. |
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/solutions/LEN-22168 |
|
History
No history.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-09-16T17:28:39.870Z
Reserved: 2018-03-27T00:00:00.000Z
Link: CVE-2018-9065
No data.
Status : Modified
Published: 2018-07-30T16:29:00.377
Modified: 2024-11-21T04:14:54.050
Link: CVE-2018-9065
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD