U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2019-6187

Change History

Initial Analysis by NIST 11/21/2019 8:00:57 PM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:a:lenovo:xclarity_controller:*:*:*:*:*:*:*:* versions up to (excluding) cdi340m
     OR
          cpe:2.3:h:lenovo:thinkagile_7d1h:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinkagile_7x83:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinkagile_7y13:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinkagile_7y14:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinkagile_7y90:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinkagile_7y93:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinkagile_7y94:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinkagile_7z04:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinkagile_7z05:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinkagile_7z06:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinkagile_7z07:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinkagile_7z20:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinkagile_yx84:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_sr530:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_sr550:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_sr570:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_sr590:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_sr630:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_sr650:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_st550:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_st558:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:a:lenovo:xclarity_controller:*:*:*:*:*:*:*:* versions up to (excluding) g1i312
     OR
          cpe:2.3:h:lenovo:_thinksystem_sr670:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:a:lenovo:xclarity_controller:*:*:*:*:*:*:*:* versions up to (excluding) psi328m
     OR
          cpe:2.3:h:lenovo:thinksystem_sr950:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:a:lenovo:xclarity_controller:*:*:*:*:*:*:*:* versions up to (excluding) tei392m
     OR
          cpe:2.3:h:lenovo:thinkagile_7x82:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinkagile_7y11:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinkagile_7y12:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinkagile_7y88:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinkagile_7y92:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinkagile_7z03:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_sd530:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_sd650:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_sn550:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_sn850:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_sr150:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_sr158:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_sr250:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_sr258:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_sr850:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_sr860:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_st250:-:*:*:*:*:*:*:*
          cpe:2.3:h:lenovo:thinksystem_st258:-:*:*:*:*:*:*:*
Added CVSS V2

								
							
							
						
NIST (AV:N/AC:L/Au:S/C:P/I:N/A:N)
Added CVSS V3.1

								
							
							
						
NIST AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Added CWE

								
							
							
						
NIST CWE-74
Changed Reference Type
https://support.lenovo.com/solutions/LEN-29118 No Types Assigned
https://support.lenovo.com/solutions/LEN-29118 Patch, Vendor Advisory