CVE-2021-45925
Observable discrepancies in the login process allow an attacker to guess legitimate user names registered in the BMC.
By supplying an arbitrary username, based on the response, an un-authenticated remote attacker would be able to determine the existence of the input username in the application.
October 21, 2022
The vulnerability affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0
CVE-2021-45925
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
5.3
Updated BMC firmware versions that fix the issue are available from Lanner technical support
Andrea Palanca of Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more

