Database/Firmware, BMC & network fabric
Lenovo XClarity Controller (LDAP mode): Read-only authentication bypass when XCC is in LDAP-only authentication mode
CVE-2021-3956Firmware, BMC & network fabriccurated
Impact
Read-only authentication bypass when XCC is in LDAP-only authentication mode
Who can reach it
Network
What to do
XCC firmware update; also affects the common neocloud pattern of centralising BMC auth in LDAP/AD
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.