PT-2020-10230 · Lenovo+1 · Lenovo Xclarity Administrator+1
Published
2020-03-13
·
Updated
2021-11-02
·
CVE-2019-19756
CVSS v3.1
7.9
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Lenovo XClarity Administrator version 2.6.0
Description
An internal product security audit discovered that Windows OS credentials used for driver updates of managed systems are being written to a log file in clear text. This issue affects the log files accessible to authorized users in the First Failure Data Capture (FFDC) service log and log files on LXCA, specifically when performing a Windows driver update.
Recommendations
For Lenovo XClarity Administrator version 2.6.0, consider restricting access to the log files in the First Failure Data Capture (FFDC) service log and log files on LXCA to minimize the risk of credential exposure until a patch is available.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lenovo Xclarity Administrator
Windows