Database/Firmware, BMC & network fabric
Lenovo XClarity Controller (XCC) - audit log: When an account username is exactly 16 characters, XCC writes the IPMI
Impact
When an account username is exactly 16 characters, XCC writes the IPMI credentials into its own audit log entries in the clear. The consequence is that anyone allowed to read BMC audit logs - a broader set than anyone allowed to administer the BMC, since logs get shipped to SIEMs, ticketing systems and shared dashboards - picks up working IPMI credentials for the node. Those credentials give power control and boot manipulation. It is a small bug with an awkward blast radius, because log data usually flows to systems with much weaker access control than the BMC itself. Affects a long list of ThinkSystem and ThinkAgile models.
Who can reach it
Anyone with read access to XCC audit logs, or to whatever downstream system those logs are forwarded into. Requires that at least one account on the node has a 16-character username, which is common where naming conventions produce fixed-length service account names.
What to do
Flash XCC to the per-model version in LEN-172051 - out-of-band, per-node, no host reboot and no drain. Two things the flash does not do, and you must: purge or re-scope any already-collected XCC audit logs sitting in your log pipeline, and rotate the IPMI credentials that were exposed. A quick config-only check meanwhile: look for 16-character usernames across the fleet, since only those trigger the leak.
References
Related entries
- Intel Xeon 6 with TDX: coarse access control in a processor subsystem exposes data to an authenticated local userCVE-2025-31938 · Intel Xeon 6 Scalable processors with Intel TDX (subsystem access control)Medium
- Arista DANZ Monitoring Fabric: debug API exposes config database contents including user password hashesCVE-2025-54548 · Arista DANZ Monitoring Fabric (debug API exposing the config database)Medium
- Self-encrypting drives in TCG Opal / eDrive modeCVE-2015-7267 · Self-encrypting drives in TCG Opal / eDrive mode - Samsung 850 Pro, Samsung PM851, Seagate ST500LT015, ST500LT025 on…Medium
- Samsung 840 EVO SSD - disk encryption key exposed through wear-levelled NAND and vendor-specific commands: The driveCVE-2018-12038 · Samsung 840 EVO SSD - disk encryption key exposed through wear-levelled NAND and vendor-specific commandsMedium
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2025-20044 · Intel TDX moduleMedium
- Crucial/Micron MX100, MX200, MX300; Samsung 840 EVO and 850 EVO (ATA-high mode)CVE-2018-12037 · Crucial/Micron MX100, MX200, MX300; Samsung 840 EVO and 850 EVO (ATA-high mode); Samsung T3 and T5 portable SSDs…Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.