Database/Firmware, BMC & network fabric
Lenovo XClarity Controller: Backup/restore password written to an internal XCC log buffer
CVSS 4.5CVE-2021-3473Firmware, BMC & network fabriccurated
Impact
Backup/restore password written to an internal XCC log buffer — credential leak to anyone who can pull BMC logs
Who can reach it
Local/network, authenticated
What to do
XCC firmware update plus rotation of any XCC backup passwords used during fleet provisioning
References
Related entries
- Intel AMT / ISM / SBT firmware anti-rollback, ME 11.0.25.3001 and 11.0.26.3000: The patched ME firmware doesCVE-2017-5698 · Intel AMT / ISM / SBT firmware anti-rollback, ME 11.0.25.3001 and 11.0.26.3000Medium
- Intel SGX protected memory subsystem: Insufficient access control in the SGX protected-memory subsystem allowsCVE-2019-0117 · Intel SGX protected memory subsystemMedium
- Intel E810 Ethernet controller firmware (NVM < 1.4.1.13): Early-generation E810 firmware flaw (an access-controlCVE-2020-24497 · Intel E810 Ethernet controller firmware (NVM < 1.4.1.13)Medium
- Intel E810 Ethernet controller firmware: privileged-local buffer overflows allow denial of serviceCVE-2020-24498 · Intel E810 Ethernet controller firmware (NVM < 1.4.1.13)Medium
- Intel E810 Ethernet controller firmware (NVM): Firmware-level flaw in the E810 network controller allowing a privilegedCVE-2021-0197 · Intel E810 Ethernet controller firmware (NVM)Medium
- Intel E810 Ethernet controller firmware (NVM): Firmware-level flaw in the E810 network controller allowing a privilegedCVE-2021-0198 · Intel E810 Ethernet controller firmware (NVM)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.