An internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/restore password may be written to an internal XCC log buffer if Lenovo XClarity Administrator (LXCA) is used to perform the backup/restore. The backup/restore password typically exists in this internal log buffer for less than 10 minutes before being overwritten. Generating an FFDC service log will include the log buffer contents, including the backup/restore password if present. The FFDC service log is only generated when requested by a privileged XCC user and it is only accessible to the privileged XCC user that requested the file. The backup/restore password is not captured if the backup/restore is initiated directly from XCC.

Project Subscriptions

Vendors Products
Thinkagile Hx1320 Subscribe
Thinkagile Hx2320 Subscribe
Thinkagile Hx3320 Subscribe
Thinkagile Hx3375 Subscribe
Thinkagile Hx3520-g Subscribe
Thinkagile Hx3720 Subscribe
Thinkagile Hx5520 Subscribe
Thinkagile Hx7520 Subscribe
Thinkagile Hx7820 Subscribe
Thinkagile Mx1020 Subscribe
Thinkagile Mx Certified Nodes Subscribe
Thinkagile Vx 1u Subscribe
Thinkagile Vx 2u Subscribe
Thinkagile Vx Dense Subscribe
Thinksystem Sd530 Subscribe
Thinksystem Sd650 Subscribe
Thinksystem Se350 Subscribe
Thinksystem Sn550 Subscribe
Thinksystem Sn850 Subscribe
Thinksystem Sr150 Subscribe
Thinksystem Sr158 Subscribe
Thinksystem Sr250 Subscribe
Thinksystem Sr258 Subscribe
Thinksystem Sr530 Subscribe
Thinksystem Sr570 Subscribe
Thinksystem Sr590 Subscribe
Thinksystem Sr630 Subscribe
Thinksystem Sr650 Subscribe
Thinksystem Sr670 Subscribe
Thinksystem Sr850 Subscribe
Thinksystem Sr850p Subscribe
Thinksystem Sr860 Subscribe
Thinksystem Sr950 Subscribe
Thinksystem St250 Subscribe
Thinksystem St258 Subscribe
Thinksystem St550 Subscribe
Thinksystem St558 Subscribe
Xclarity Controller Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-26795 An internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/restore password may be written to an internal XCC log buffer if Lenovo XClarity Administrator (LXCA) is used to perform the backup/restore. The backup/restore password typically exists in this internal log buffer for less than 10 minutes before being overwritten. Generating an FFDC service log will include the log buffer contents, including the backup/restore password if present. The FFDC service log is only generated when requested by a privileged XCC user and it is only accessible to the privileged XCC user that requested the file. The backup/restore password is not captured if the backup/restore is initiated directly from XCC.
Fixes

Solution

Update to the Lenovo XClarity Controller (XCC) version (or higher) as recommended in the Product Impact section of LEN-52117.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-03T16:53:17.827Z

Reserved: 2021-03-29T00:00:00

Link: CVE-2021-3473

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-13T21:15:25.410

Modified: 2024-11-21T06:21:37.620

Link: CVE-2021-3473

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses