CVE-2015-3322
Summary
| CVE | CVE-2015-3322 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-04-16 23:59:00 UTC |
| Updated | 2017-01-18 02:59:00 UTC |
| Description | Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passwords, which allows attackers to decrypt the passwords via unspecified vectors. |
Risk And Classification
Problem Types: CWE-310
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Lenovo | Thinkserver Rd350 | All | All | All | All |
| Hardware | Lenovo | Thinkserver Rd350 | All | All | All | All |
| Operating System | Lenovo | Thinkserver Rd350 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkserver Rd450 | All | All | All | All |
| Hardware | Lenovo | Thinkserver Rd450 | All | All | All | All |
| Operating System | Lenovo | Thinkserver Rd450 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkserver Rd550 | All | All | All | All |
| Hardware | Lenovo | Thinkserver Rd550 | All | All | All | All |
| Operating System | Lenovo | Thinkserver Rd550 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkserver Rd650 | All | All | All | All |
| Hardware | Lenovo | Thinkserver Rd650 | All | All | All | All |
| Operating System | Lenovo | Thinkserver Rd650 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkserver Td350 | All | All | All | All |
| Hardware | Lenovo | Thinkserver Td350 | All | All | All | All |
| Operating System | Lenovo | Thinkserver Td350 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Lenovo Products CVE-2015-3322 BIOS Password Encryption Weakness | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| ThinkServer *50-series BIOS Password Encryption Weakness - Lenovo Support (US) | CONFIRM | support.lenovo.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.