CVE-2015-3324
Summary
| CVE | CVE-2015-3324 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-04-16 23:59:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "encrypted remote KVM session," which allows man-in-the-middle attackers to spoof servers. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Lenovo | Thinkserver Rd350 | - | All | All | All |
| Hardware | Lenovo | Thinkserver Rd450 | - | All | All | All |
| Hardware | Lenovo | Thinkserver Rd550 | - | All | All | All |
| Hardware | Lenovo | Thinkserver Rd650 | - | All | All | All |
| Operating System | Lenovo | Thinkserver System Manager Baseboard Management Controller Firmware | 118.71532 | All | All | All |
| Hardware | Lenovo | Thinkserver Td350 | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Lenovo ThinkServer System Manager CVE-2015-3324 Certificate Validation Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Multiple ThinkServer System Manager (TSM) *50-series Security Weaknesses - Lenovo Support (US) | af854a3a-2127-422b-91ae-364da2661108 | support.lenovo.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.