Vulnerability Description
A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting XCC devices configured in LDAP Authentication Only Mode and using an LDAP server that supports “unauthenticated bind”, such as Microsoft Active Directory. An unauthenticated user can gain read-only access to XCC in such a configuration, thereby allowing the XCC device configuration to be viewed but not changed. XCC devices configured to use local authentication, LDAP Authentication + Authorization Mode, or LDAP servers that support only “authenticated bind” and/or “anonymous bind” are not affected.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Xclarity Controller | < 7.22_cdi382o |
| Lenovo | Thinkagile Hx1320 | - |
| Lenovo | Thinkagile Hx1321 | - |
| Lenovo | Thinkagile Hx1520-R | - |
| Lenovo | Thinkagile Hx1521-R | - |
| Lenovo | Thinkagile Hx2320-E | - |
| Lenovo | Thinkagile Hx2321 | - |
| Lenovo | Thinkagile Hx3320 | - |
| Lenovo | Thinkagile Hx3321 | - |
| Lenovo | Thinkagile Hx3375 | - |
| Lenovo | Thinkagile Hx3376 | - |
| Lenovo | Thinkagile Hx3520-G | - |
| Lenovo | Thinkagile Hx3521-G | - |
| Lenovo | Thinkagile Hx5520 | - |
| Lenovo | Thinkagile Hx5520-C | - |
| Lenovo | Thinkagile Hx5521 | - |
| Lenovo | Thinkagile Hx5521-C | - |
| Lenovo | Thinkagile Hx7520 | - |
| Lenovo | Thinkagile Hx7521 | - |
| Lenovo | Thinkagile Vx2320 | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/LEN-72074Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-72074Vendor Advisory
FAQ
What is CVE-2021-3956?
CVE-2021-3956 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting XCC devices configured in LDAP Authentication Only...
How severe is CVE-2021-3956?
CVE-2021-3956 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3956?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Xclarity Controller, Lenovo Thinkagile Hx1320, Lenovo Thinkagile Hx1321, Lenovo Thinkagile Hx1520-R, Lenovo Thinkagile Hx1521-R.