PT-2020-10230 · Lenovo+1 · Lenovo Xclarity Administrator+1

Published

2020-03-13

·

Updated

2021-11-02

·

CVE-2019-19756

CVSS v3.1

7.9

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Lenovo XClarity Administrator version 2.6.0
Description An internal product security audit discovered that Windows OS credentials used for driver updates of managed systems are being written to a log file in clear text. This issue affects the log files accessible to authorized users in the First Failure Data Capture (FFDC) service log and log files on LXCA, specifically when performing a Windows driver update.
Recommendations For Lenovo XClarity Administrator version 2.6.0, consider restricting access to the log files in the First Failure Data Capture (FFDC) service log and log files on LXCA to minimize the risk of credential exposure until a patch is available.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19756

Affected Products

Lenovo Xclarity Administrator
Windows