LiveActive security incident?Get immediate response
CVE Record

CVE-2019-6187: A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an a...

A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysislow

Security readout for executives and security teams

Plain-English summary

Lenovo XClarity Controller had a stored CSV injection issue. A privileged user could save malformed data into server information fields so exported CSV files contain spreadsheet formulas. The formula does not run on XCC and does not affect the server; risk appears tied to someone later opening the CSV in a spreadsheet.

Executive priority

Handle through normal vulnerability management unless CSV exports from XCC are widely used in sensitive workflows. The server itself is not affected by formula execution, but downstream spreadsheet handling may create user-side risk.

Technical view

CVE-2019-6187 affects Lenovo XClarity Controller. The source describes stored formula content in exported CSVs from certain XCC server informational fields, requiring an administrative or otherwise permissioned user. No CVSS, CWE, affected version detail, patch detail, or active exploitation evidence is included in the bundle.

Likely exposure

Exposure is most likely in organizations using Lenovo XClarity Controller where privileged users can edit server informational fields and staff export CSV data for spreadsheet review. The source bundle does not identify exact affected XCC versions.

Exploitation context

The provided sources do not support active exploitation, and the CVE is not marked KEV. The described behavior does not execute on XCC itself; the practical risk is downstream CSV handling by a spreadsheet application.

Researcher notes

Key unknowns are exact affected versions, vendor fix details, and any spreadsheet-specific impact conditions. The source explicitly narrows impact: crafted formulas are stored in exported CSV files and are not executed on XCC.

Mitigation direction

  • Review Lenovo advisory LEN-29118 for affected versions and vendor remediation.
  • Limit who can edit XCC server informational fields.
  • Treat XCC CSV exports as untrusted data before spreadsheet use.
  • Ask Lenovo support for guidance if firmware exposure cannot be confirmed.

Validation and detection

  • Inventory Lenovo XClarity Controller deployments and firmware versions.
  • Check whether XCC CSV exports are used in operational workflows.
  • Review permissions for users able to edit server informational fields.
  • Compare deployment details against Lenovo advisory LEN-29118.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2019-6187 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LenovoLenovo XClarity Controller (XCC)unspecified, unspecified, unspecified, unspecifiedListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.