{"api_version":"1","generated_at":"2026-07-23T09:27:06+00:00","cve":"CVE-2017-3764","urls":{"html":"https://cve.report/CVE-2017-3764","api":"https://cve.report/api/cve/CVE-2017-3764.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-3764","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-3764"},"summary":{"title":"CVE-2017-3764","description":"A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated users with access to the LXCA web user interface. No password information of the user accounts is exposed.","state":"PUBLISHED","assigner":"lenovo","published_at":"2017-11-30 19:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-200","Unauthenticated User Enumeration"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://support.lenovo.com/us/en/product_security/LEN-16335","name":"https://support.lenovo.com/us/en/product_security/LEN-16335","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"LXCA User Account Names Exposed To Unauthenticated Users Who Can Access the Web User Interface - Lenovo Support US","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-3764","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-3764","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Lenovo Group Ltd.","product":"xClarity Administrator","version":"affected Earlier than 1.4.0","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"3764","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"lenovo","cpe5":"xclarity_administrator","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2017","cve_id":"3764","cve":"CVE-2017-3764","epss":"0.007340000","percentile":"0.729090000","score_date":"2026-05-14","updated_at":"2026-05-15 00:08:13"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T14:39:40.402Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.lenovo.com/us/en/product_security/LEN-16335"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"xClarity Administrator","vendor":"Lenovo Group Ltd.","versions":[{"status":"affected","version":"Earlier than 1.4.0"}]}],"datePublic":"2017-11-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated users with access to the LXCA web user interface. No password information of the user accounts is exposed."}],"problemTypes":[{"descriptions":[{"description":"Unauthenticated User Enumeration","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-11-30T18:57:01.000Z","orgId":"da227ddf-6e25-4b41-b023-0f976dcaca4b","shortName":"lenovo"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://support.lenovo.com/us/en/product_security/LEN-16335"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@lenovo.com","DATE_PUBLIC":"2017-11-30T00:00:00","ID":"CVE-2017-3764","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"xClarity Administrator","version":{"version_data":[{"version_value":"Earlier than 1.4.0"}]}}]},"vendor_name":"Lenovo Group Ltd."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated users with access to the LXCA web user interface. No password information of the user accounts is exposed."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Unauthenticated User Enumeration"}]}]},"references":{"reference_data":[{"name":"https://support.lenovo.com/us/en/product_security/LEN-16335","refsource":"CONFIRM","url":"https://support.lenovo.com/us/en/product_security/LEN-16335"}]}}}},"cveMetadata":{"assignerOrgId":"da227ddf-6e25-4b41-b023-0f976dcaca4b","assignerShortName":"lenovo","cveId":"CVE-2017-3764","datePublished":"2017-11-30T19:00:00.000Z","dateReserved":"2016-12-16T00:00:00.000Z","dateUpdated":"2024-09-17T02:46:43.637Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-11-30 19:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-200","Unauthenticated User Enumeration"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:lenovo:xclarity_administrator:*:*:*:*:*:*:*:*","versionEndExcluding":"1.4.0","matchCriteriaId":"070219DA-DDD4-4E8A-A23B-3E46E4CB37DA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"3764","Ordinal":"1","Title":"CVE-2017-3764","CVE":"CVE-2017-3764","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"3764","Ordinal":"1","NoteData":"A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated users with access to the LXCA web user interface. No password information of the user accounts is exposed.","Type":"Description","Title":"CVE-2017-3764"},{"CveYear":"2017","CveId":"3764","Ordinal":"2","NoteData":"2017-11-30","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"3764","Ordinal":"3","NoteData":"2017-11-30","Type":"Other","Title":"Modified"}]}}}