Database/Firmware, BMC & network fabric
Lenovo XClarity Controller (XCC) - LDAP/AD authorization: When XCC is configured to authenticate against Active
Impact
When XCC is configured to authenticate against Active Directory, a user's local XCC account permissions silently override the permissions their directory group grants - and the local ones can be higher. The result is privilege escalation that your identity provider cannot see: you revoke someone's admin rights in AD, XCC keeps honouring the stale local grant, and they retain out-of-band control of the node. For an operator this is a offboarding and least-privilege failure more than an exploit, which makes it easy to miss - nothing looks broken, and the directory tells you the access is gone.
Who can reach it
A valid XCC user in a deployment where LDAP/AD is configured for authentication and authorisation and the user also has a local XCC account. No exploit code required - the misbehaviour is in the authorisation logic itself.
What to do
Flash XCC to the version listed for your model in LEN-118321 - out-of-band, per-node, no host reboot and no drain. Alongside the flash, do the config work that actually closes the gap: enumerate local XCC accounts on every node and delete the ones that shadow directory identities, because patching the precedence logic does not remove local accounts that are already there.
References
Related entries
- BMC firmware for Intel Server Boards S2600WF / S2600ST / S2600BP before 02.01.0017 and M50CYP, and OpenBMC firmwareCVE-2023-29164 · BMC firmware for Intel Server Boards S2600WF / S2600ST / S2600BP before 02.01.0017 and M50CYP, and OpenBMC firmware…High
- Linux bnxt_en driver (bnxt_fill_hw_rss_tbl): Memory out-of-bounds in the RSS indirection-table path of the Broadcom NICCVE-2024-44933 · Linux bnxt_en driver (bnxt_fill_hw_rss_tbl)High
- Linux kernel mpi3mr driver (Broadcom tri-mode 9600-series HBA/RAID) and megaraid_sas driver: Rapidly toggling PHYCVE-2024-57804 · Linux kernel mpi3mr driver (Broadcom tri-mode 9600-series HBA/RAID) and megaraid_sas driverHigh
- BullSequana XH3406/XH3515 BMC: factory reset can leave root enabled with no passwordCVE-2025-15679 · BullSequana XH3406 / XH3515 BMC (root account after factory reset)High
- AMI AptioV UEFI BIOS: A race condition in the BIOS that a skilled local attacker can drive to resource exhaustionCVE-2025-22830 · AMI AptioV UEFI BIOSHigh
- AMI AptioV BIOS (unchecked buffer copy): Buffer copy without size checking in firmware leading to arbitrary codeCVE-2025-22833 · AMI AptioV BIOS (unchecked buffer copy)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.