CVE-2015-3322
Summary
| CVE | CVE-2015-3322 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-04-16 23:59:03 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passwords, which allows attackers to decrypt the passwords via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Lenovo | Thinkserver Rd350 | All | All | All | All |
| Operating System | Lenovo | Thinkserver Rd350 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkserver Rd450 | All | All | All | All |
| Operating System | Lenovo | Thinkserver Rd450 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkserver Rd550 | All | All | All | All |
| Operating System | Lenovo | Thinkserver Rd550 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkserver Rd650 | All | All | All | All |
| Operating System | Lenovo | Thinkserver Rd650 Firmware | All | All | All | All |
| Hardware | Lenovo | Thinkserver Td350 | All | All | All | All |
| Operating System | Lenovo | Thinkserver Td350 Firmware | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ThinkServer *50-series BIOS Password Encryption Weakness - Lenovo Support (US) | af854a3a-2127-422b-91ae-364da2661108 | support.lenovo.com | Patch, Vendor Advisory |
| Multiple Lenovo Products CVE-2015-3322 BIOS Password Encryption Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.