CVE-2016-8221

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
12/01/2017
Last modified:
20/04/2025

Description

Privilege Escalation in Lenovo XClarity Administrator earlier than 1.2.0, if LXCA is used to manage rack switches or chassis with embedded input/output modules (IOMs), certain log files viewable by authenticated users may contain passwords for internal administrative LXCA accounts with temporary passwords that are used internally by LXCA code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lenovo:xclarity_administrator:*:*:*:*:*:*:*:* 1.1.1 (including)