CVE-2019-6158
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.7epss 1.5%
exploitation probability
1.5%top 29% of all CVEs
observed exploitation
nono source reports it
In short
Lenovo XClarity Administrator writes HTTP proxy login credentials in clear text to log files, allowing anyone with access to those files to steal them. This only happens if an HTTP proxy with credentials has been configured.
Technical detail
HTTP proxy credentials are logged in plaintext in LXCA versions 2.0.0–2.3.x when proxy authentication is configured. An attacker with local or remote access to log files can extract these credentials without authentication, leading to unauthorized proxy access and potential network interception.
Summary generated and translated by AI from the official description.
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being written to a log file in clear text. This only affects LXCA when HTTP proxy credentials have been configured. This affects LXCA versions 2.0.0 to 2.3.x.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Affected products
Lenovo · Lenovo XClarity Administrator