Credential Exposure in Lenovo xClarity Administrator
CVE-2018-9065
7.5HIGH
Summary
In Lenovo xClarity Administrator prior to version 2.1.0, an attacker with access to the LXCA file system may exploit a vulnerability to obtain a credential store. This store holds sensitive service processor usernames and passwords associated with servers previously managed by that LXCA instance. The attacker can potentially decrypt these credentials more easily than intended, which poses a significant security risk.
Affected Version(s)
Lenovo xClarity Administrator Earlier than 2.1.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved