GPU VulnDB

Database/Firmware, BMC & network fabric

Lenovo XClarity Controller (XCC) - audit log: When an account username is exactly 16 characters, XCC writes the IPMI

CVE-2024-8059Firmware, BMC & network fabricLEN-172051curated

Impact

When an account username is exactly 16 characters, XCC writes the IPMI credentials into its own audit log entries in the clear. The consequence is that anyone allowed to read BMC audit logs - a broader set than anyone allowed to administer the BMC, since logs get shipped to SIEMs, ticketing systems and shared dashboards - picks up working IPMI credentials for the node. Those credentials give power control and boot manipulation. It is a small bug with an awkward blast radius, because log data usually flows to systems with much weaker access control than the BMC itself. Affects a long list of ThinkSystem and ThinkAgile models.

Who can reach it

Anyone with read access to XCC audit logs, or to whatever downstream system those logs are forwarded into. Requires that at least one account on the node has a 16-character username, which is common where naming conventions produce fixed-length service account names.

What to do

Flash XCC to the per-model version in LEN-172051 - out-of-band, per-node, no host reboot and no drain. Two things the flash does not do, and you must: purge or re-scope any already-collected XCC audit logs sitting in your log pipeline, and rotate the IPMI credentials that were exposed. A quick config-only check meanwhile: look for 16-character usernames across the fleet, since only those trigger the leak.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.