AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-6195

MEDIUM · CVSS 4.8 EPSS 0.64%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-02-14 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.8. Exploitation may require the attacker to be authenticated.

CVE
CVE-2019-6195
Severity
MEDIUM
CVSS
4.8
EPSS
0.64%

Original NVD Description

An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to higher-privileged information if 1) “LDAP Authentication Only with Local Authorization” mode is configured and used by XCC, and 2) a lesser privileged user logs into XCC within 1 minute of a higher privileged user logging out. The authorization bypass does not exist when “Local Authentication and Authorization” or “LDAP Authentication and Authorization” modes are configured and used by XCC.

Related CVEs

Other vulnerabilities affecting the same vendor(s)