Database/Firmware, BMC & network fabric
Lenovo XClarity Controller (XCC): Authorization bypass
CVSS 4.8CVE-2019-6195Firmware, BMC & network fabriccurated
Impact
Authorization bypass — a low-privilege authenticated user gains read access beyond their role
Who can reach it
Network / XCC web
What to do
XCC firmware update; low CVSS but relevant where BMC access is delegated to tenants or remote-hands staff
References
Related entries
- ARM Trusted Firmware in AMD Zynq UltraScale+ MPSoC/RFSoC: Improper input validation in the ARM Trusted Firmware usedCVE-2023-31339 · ARM Trusted Firmware in AMD Zynq UltraScale+ MPSoC/RFSoCMedium
- AMD Secure Processor bootloader - legacy recovery mode: Insufficient input sanitisation in the ASP bootloader's legacyCVE-2025-29949 · AMD Secure Processor bootloader - legacy recovery modeMedium
- Junos OS Evolved: OS command injection in the CLI lets a low-privileged operator escalateCVE-2025-60006 · Juniper Junos OS Evolved (CLI command option handling)Medium
- Intel SGX SDK (Edger8r generated code, side channel): Edger8r generated bridge code that was susceptible to a sideCVE-2018-3626 · Intel SGX SDK (Edger8r generated code, side channel)Medium
- AMD processors - PREFETCH instruction timing and power side channel: Timing and power measurements around the x86CVE-2021-26318 · AMD processors - PREFETCH instruction timing and power side channelMedium
- AMD processors with SMT - speculative execution across SMT mode switch: With SMT enabled, certain AMD processorsCVE-2022-27672 · AMD processors with SMT - speculative execution across SMT mode switchMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.