CVE-2024-8059

MEDIUM

IPMI < unknown - Info Disclosure

Title source: llm
STIX 2.1

Description

IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.

Scores

CVSS v3 4.3
EPSS 0.0007
EPSS Percentile 20.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-319
Status published
Products (50)
Lenovo/HX Enclosure Certified Node (ThinkAgile) XCC < 6.40 TEI3F3E
Lenovo/HX1021 Edge Certified Node 3yr (ThinkAgile) XCC < 4.12 TEI3E4D
Lenovo/HX1320 Appliance (ThinkAgile) XCC < 9.98 CDI3B4E
Lenovo/HX1321 Certified Node (ThinkAgile) XCC < 9.98 CDI3B4E
Lenovo/HX1331 Certified Node (ThinkAgile) XCC < 5.10 AFBT50F
Lenovo/HX1520-R Appliance (ThinkAgile) XCC < 9.98 CDI3B4E
Lenovo/HX1521-R Certified Node (ThinkAgile) XCC < 9.98 CDI3B4E
Lenovo/HX2320-E Appliance (ThinkAgile) XCC < 9.98 CDI3B4E
Lenovo/HX2321 Certified Node (ThinkAgile) XCC < 9.98 CDI3B4E
Lenovo/HX2330 Appliance (ThinkAgile) XCC < 5.10 AFBT50F
... and 40 more
Published Sep 13, 2024
Tracked Since Feb 18, 2026