ID

VAR-201706-0356


CVE

CVE-2017-3745


TITLE

Lenovo XClarity Administrator Authentication vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2017-005067

DESCRIPTION

In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to password information for users that have previously authenticated to the LXCA's internal LDAP server, including administrative accounts and service accounts with administrative privileges. This is an issue only for users who have used local authentication with LXCA and not remote authentication against external LDAP or ADFS servers. Lenovo XClarity Administrator (LXCA) Contains an authentication vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Lenovo XClarity Administrator is prone to an information-disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may aid in further attacks. Lenovo XClarity Administrator (LXCA) is a set of centralized resource management solutions of China Lenovo (Lenovo). The solution supports simplified infrastructure management, faster server response, and improved Lenovo server system performance. A security vulnerability exists in versions prior to LXCA 1.3.0

Trust: 1.98

sources: NVD: CVE-2017-3745 // JVNDB: JVNDB-2017-005067 // BID: 99347 // VULHUB: VHN-111948

AFFECTED PRODUCTS

vendor:lenovomodel:xclarity administratorscope:lteversion:1.2.2

Trust: 1.0

vendor:lenovomodel:xclarity administratorscope:eqversion:1.2.2

Trust: 0.9

vendor:lenovomodel:xclarity administratorscope:ltversion:1.3.0

Trust: 0.8

vendor:lenovomodel:xclarity administratorscope:neversion:1.3

Trust: 0.3

sources: BID: 99347 // JVNDB: JVNDB-2017-005067 // CNNVD: CNNVD-201706-790 // NVD: CVE-2017-3745

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-3745
value: HIGH

Trust: 1.0

NVD: CVE-2017-3745
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201706-790
value: LOW

Trust: 0.6

VULHUB: VHN-111948
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2017-3745
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-111948
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-3745
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-111948 // JVNDB: JVNDB-2017-005067 // CNNVD: CNNVD-201706-790 // NVD: CVE-2017-3745

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.9

sources: VULHUB: VHN-111948 // JVNDB: JVNDB-2017-005067 // NVD: CVE-2017-3745

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201706-790

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-201706-790

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-005067

PATCH

title:LEN-13671url:https://support.lenovo.com/jp/ja/product_security/len-13671

Trust: 0.8

title:Lenovo XClarity Administrator Repair measures for information disclosure vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=71074

Trust: 0.6

sources: JVNDB: JVNDB-2017-005067 // CNNVD: CNNVD-201706-790

EXTERNAL IDS

db:NVDid:CVE-2017-3745

Trust: 2.8

db:LENOVOid:LEN-13671

Trust: 2.0

db:JVNDBid:JVNDB-2017-005067

Trust: 0.8

db:CNNVDid:CNNVD-201706-790

Trust: 0.7

db:BIDid:99347

Trust: 0.4

db:VULHUBid:VHN-111948

Trust: 0.1

sources: VULHUB: VHN-111948 // BID: 99347 // JVNDB: JVNDB-2017-005067 // CNNVD: CNNVD-201706-790 // NVD: CVE-2017-3745

REFERENCES

url:https://support.lenovo.com/us/en/product_security/len-13671

Trust: 2.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-3745

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-3745

Trust: 0.8

url:http://www.lenovo.com/ca/en/

Trust: 0.3

sources: VULHUB: VHN-111948 // BID: 99347 // JVNDB: JVNDB-2017-005067 // CNNVD: CNNVD-201706-790 // NVD: CVE-2017-3745

CREDITS

Lenovo

Trust: 0.3

sources: BID: 99347

SOURCES

db:VULHUBid:VHN-111948
db:BIDid:99347
db:JVNDBid:JVNDB-2017-005067
db:CNNVDid:CNNVD-201706-790
db:NVDid:CVE-2017-3745

LAST UPDATE DATE

2024-11-23T22:34:37.482000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-111948date:2017-06-30T00:00:00
db:BIDid:99347date:2017-06-19T00:00:00
db:JVNDBid:JVNDB-2017-005067date:2017-07-13T00:00:00
db:CNNVDid:CNNVD-201706-790date:2017-06-20T00:00:00
db:NVDid:CVE-2017-3745date:2024-11-21T03:26:03.330

SOURCES RELEASE DATE

db:VULHUBid:VHN-111948date:2017-06-20T00:00:00
db:BIDid:99347date:2017-06-19T00:00:00
db:JVNDBid:JVNDB-2017-005067date:2017-07-13T00:00:00
db:CNNVDid:CNNVD-201706-790date:2017-06-20T00:00:00
db:NVDid:CVE-2017-3745date:2017-06-20T00:29:00.360