OOB Read in Lighttpd 1.4.35 used in Lenovo BMC firmware
BINARLY team has discovered a Heap Out-of-bounds Read vulnerability in the web server component of Lenovo BMC firmware, allowing a potential attacker to exfiltrate sensitive information from Lighttpd process memory.
Image preview
Get started today, Ship and Buy Software You Can Prove Is Safe
Book a live tour to watch Binarly validate SBOM/CBOM, surface exploitable risks, and chart a path to post-quantum readiness.
Potential Impact
A potential attacker can exploit this vulnerability in order to read memory of Lighttpd Web Server process. This may lead to sensitive data exfiltration, such as memory addresses, which can be used to bypass security mechanisms such as ASLR.
Image preview
Vulnerability Information
- BINARLY internal vulnerability identifier: BRLY-2024-003
- BINARLY calculated CVSS v3.1: 5.3 Medium AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Image preview
Get started today, Ship and Buy Software You Can Prove Is Safe
Book a live tour to watch Binarly validate SBOM/CBOM, surface exploitable risks with reachability and exploitation maturity scoring, and chart a measurable path to post-quantum readiness.