CVE-2019-6161
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB (Storage Block) BMC in firmware versions prior to 1908.M. This vulnerability allows session IDs to be reused, which could provide unauthorized access to the BMC under certain circumstances. This vulnerability does not affect ThinkSystem XCC, System x IMM2, or other BMCs.
Una auditoría de seguridad de producto interna detectó una vulnerabilidad de manejo de sesión en la interfaz web de ThinkAgile CP-SB (Storage Block) BMC en versiones de firmware anteriores a 1908.M. Esta vulnerabilidad permite que los ID de sesión sean reutilizados, lo que podría proporcionar acceso no autorizado al BMC en determinadas circunstancias. Esta vulnerabilidad no afecta a ThinkSystem XCC, System x IMM2 u otros BMC.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-11 CVE Reserved
- 2019-09-26 CVE Published
- 2023-03-07 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-384: Session Fixation
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.lenovo.com/solutions/LEN-26957 | 2019-10-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Lenovo Search vendor "Lenovo" | Cp Storage Block Firmware Search vendor "Lenovo" for product "Cp Storage Block Firmware" | < 1908.m Search vendor "Lenovo" for product "Cp Storage Block Firmware" and version " < 1908.m" | - |
Affected
| in | Lenovo Search vendor "Lenovo" | Cp Storage Block Search vendor "Lenovo" for product "Cp Storage Block" | - | - |
Safe
|