CVE-2021-3473 describes a vulnerability in Lenovo XClarity Controller (XCC) where the configuration backup/restore password may be temporarily written to an internal XCC log buffer if the operation is initiated via Lenovo XClarity Administrator (LXCA). This sensitive information, present for less than 10 minutes, could then be included in an FFDC service log generated by a privileged XCC user. The vulnerability has a CVSS score of 4.9 (Medium) with an attack vector of Network and high confidentiality impact, but requires high privileges (PR:H) and no user interaction. While an attacker could potentially gain access to the backup/restore password, this requires an already privileged XCC user to generate and access the FFDC log. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE. Its EPSS score is very low, indicating a minimal likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.00_cdi370qCPE matchmatch criteria | cpe:2.3:a:lenovo:xclarity_controller:6.00_cdi370q:*:*:*:*:*:*:* | ||
1.10_tgbt12qCPE matchmatch criteria | cpe:2.3:a:lenovo:xclarity_controller:1.10_tgbt12q:*:*:*:*:*:*:* | ||
2.14_psi338iCPE matchmatch criteria | cpe:2.3:a:lenovo:xclarity_controller:2.14_psi338i:*:*:*:*:*:*:* | ||
4.40_tei3b2pCPE matchmatch criteria | cpe:2.3:a:lenovo:xclarity_controller:4.40_tei3b2p:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.