PT-2020-11196 · Lenovo · Lenovo Xclarity Administrator

Published

2020-02-14

·

Updated

2020-02-24

·

CVE-2019-6193

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6
Description An information disclosure issue was reported that could allow unauthenticated access to some configuration files. These files may contain sensitive information such as usernames, license keys, IP addresses, and encrypted password hashes.
Recommendations For versions prior to 2.6.6, update to version 2.6.6 or later to resolve the issue.

Fix

Improper Access Control

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-6193

Affected Products

Lenovo Xclarity Administrator