← back
CVE-2019-6158high

CVE-2019-6158

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.7epss 1.5%
exploitation probability
1.5%top 29% of all CVEs
observed exploitation
nono source reports it
In short

Lenovo XClarity Administrator writes HTTP proxy login credentials in clear text to log files, allowing anyone with access to those files to steal them. This only happens if an HTTP proxy with credentials has been configured.

Technical detail

HTTP proxy credentials are logged in plaintext in LXCA versions 2.0.0–2.3.x when proxy authentication is configured. An attacker with local or remote access to log files can extract these credentials without authentication, leading to unauthorized proxy access and potential network interception.

Summary generated and translated by AI from the official description.
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being written to a log file in clear text. This only affects LXCA when HTTP proxy credentials have been configured. This affects LXCA versions 2.0.0 to 2.3.x.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N