PT-2019-17994 · Lenovo · Thinkagile Cp-Sb

Publicado

2019-09-26

·

Atualizado

2019-10-01

·

CVE-2019-6161

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ThinkAgile CP-SB (Storage Block) BMC versions prior to 1908.M
Description An internal product security audit discovered a session handling issue in the web interface of the affected product. This issue allows session IDs to be reused, potentially providing unauthorized access to the BMC under certain circumstances.
Recommendations For versions prior to 1908.M, update the firmware to version 1908.M or later to resolve the issue. As a temporary workaround, consider restricting access to the web interface to minimize the risk of exploitation.

Correção

Session Fixation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-6161

Produtos afetados

Thinkagile Cp-Sb