VYPR
Unrated severityNVD Advisory· Published Oct 24, 2022· Updated May 7, 2025

Username Enumeration

CVE-2021-45925

Description

Observable discrepancies in the login process allow an attacker to guess legitimate user names registered in the BMC. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Observable discrepancies in the login process of Lanner IAC-AST2500A BMC firmware allow unauthenticated attackers to enumerate valid usernames.

Vulnerability

Observable discrepancies in the login process of the Lanner IAC-AST2500A Baseboard Management Controller (BMC) running standard firmware version 1.10.0 allow an attacker to determine whether a given username is registered [2]. The firmware is based on the AMI MegaRAC SP-X solution [1]. The vulnerability exists in the authentication mechanism where the response differs depending on whether the username exists.

Exploitation

An unauthenticated remote attacker can send login requests with arbitrary usernames to the BMC's web interface or API. By analyzing the response (e.g., error messages, timing differences), the attacker can infer the existence of the username [2]. No prior authentication or special privileges are required; only network access to the BMC is needed.

Impact

Successful exploitation allows the attacker to enumerate valid usernames registered on the BMC. This information disclosure (low confidentiality impact) can be used as a stepping stone for further attacks, such as password guessing or targeted credential stuffing [2]. The CVSS score is 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) [2].

Mitigation

Lanner has released updated BMC firmware versions that fix the issue; these are available from Lanner technical support [2]. Asset owners should contact Lanner to obtain the patched firmware. No workarounds are documented. The affected version is 1.10.0; upgrading to a fixed version is recommended.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.