Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Customers should update to the version (or later) of Lenovo XClarity Controller (XCC) identified in the related Lenovo Product Security Advisory: https://support.lenovo.com/us/en/product_security/LEN-118321 https://support.lenovo.com/us/en/product_security/LEN-118321
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-32659 | A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined. |
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-118321 |
|
Thu, 30 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2025-01-30T18:26:37.319Z
Reserved: 2023-03-30T12:46:45.646Z
Link: CVE-2023-29056
Updated: 2024-08-02T14:00:14.660Z
Status : Modified
Published: 2023-04-28T22:15:09.073
Modified: 2024-11-21T07:56:27.923
Link: CVE-2023-29056
No data.
OpenCVE Enrichment
No data.
EUVD