CVE Vulnerabilities

CVE-2024-8059

Cleartext Transmission of Sensitive Information

Published: Sep 13, 2024 | Modified: Sep 14, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Potential Mitigations

References