An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB (Storage Block) BMC in firmware versions prior to 1908.M. This vulnerability allows session IDs to be reused, which could provide unauthorized access to the BMC under certain circumstances. This vulnerability does not affect ThinkSystem XCC, System x IMM2, or other BMCs.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published: 2019-09-26T15:22:15.136039Z

Updated: 2024-09-17T01:37:00.542Z

Reserved: 2019-01-11T00:00:00

Link: CVE-2019-6161

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-09-26T16:15:11.970

Modified: 2019-10-01T13:38:44.840

Link: CVE-2019-6161

cve-icon Redhat

No data.