CVE-2015-3324
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD
Description
The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "encrypted remote KVM session," which allows man-in-the-middle attackers to spoof servers.
Affected (1)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 118.71532 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkserver Rd350 | All versions |
Lenovo Thinkserver Rd450 | All versions |
Lenovo Thinkserver Rd550 | All versions |
Lenovo Thinkserver Rd650 | All versions |
Lenovo Thinkserver Td350 | All versions |
Related CWEs
References (4)
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.