Loading HuntDB...

GHSA-4jq6-g4xr-95fp

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB (Storage Block) BMC in firmware versions prior to 1908.M. This vulnerability allows session IDs to be reused, which could provide unauthorized access to the BMC under certain circumstances. This vulnerability does not affect ThinkSystem XCC, System x IMM2, or other BMCs.

Related CVEs

Key Information

GHSA ID
GHSA-4jq6-g4xr-95fp
Published
May 24, 2022 4:56 PM
Last Modified
April 4, 2024 2:00 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 13, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.