CVE-2019-6161
Summary
| CVE | CVE-2019-6161 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-26 16:15:00 UTC |
| Updated | 2019-10-01 13:38:00 UTC |
| Description | An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB (Storage Block) BMC in firmware versions prior to 1908.M. This vulnerability allows session IDs to be reused, which could provide unauthorized access to the BMC under certain circumstances. This vulnerability does not affect ThinkSystem XCC, System x IMM2, or other BMCs. |
Risk And Classification
Problem Types: CWE-384
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Lenovo | Cp Storage Block | - | All | All | All |
| Hardware | Lenovo | Cp Storage Block | - | All | All | All |
| Operating System | Lenovo | Cp Storage Block Firmware | All | All | All | All |
| Operating System | Lenovo | Cp Storage Block Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ThinkAgile CP-SB (Storage Block) BMC Session Handling Vulnerability - TH | MISC | support.lenovo.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.