CVE-2015-3324
Summary
| CVE | CVE-2015-3324 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-04-16 23:59:00 UTC |
| Updated | 2016-12-06 02:59:00 UTC |
| Description | The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "encrypted remote KVM session," which allows man-in-the-middle attackers to spoof servers. |
Risk And Classification
Problem Types: CWE-310
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Lenovo | Thinkserver Rd350 | - | All | All | All |
| Hardware | Lenovo | Thinkserver Rd350 | - | All | All | All |
| Hardware | Lenovo | Thinkserver Rd450 | - | All | All | All |
| Hardware | Lenovo | Thinkserver Rd450 | - | All | All | All |
| Hardware | Lenovo | Thinkserver Rd550 | - | All | All | All |
| Hardware | Lenovo | Thinkserver Rd550 | - | All | All | All |
| Hardware | Lenovo | Thinkserver Rd650 | - | All | All | All |
| Hardware | Lenovo | Thinkserver Rd650 | - | All | All | All |
| Operating System | Lenovo | Thinkserver System Manager Baseboard Management Controller Firmware | 118.71532 | All | All | All |
| Operating System | Lenovo | Thinkserver System Manager Baseboard Management Controller Firmware | 118.71532 | All | All | All |
| Hardware | Lenovo | Thinkserver Td350 | - | All | All | All |
| Hardware | Lenovo | Thinkserver Td350 | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple ThinkServer System Manager (TSM) *50-series Security Weaknesses - Lenovo Support (US) | CONFIRM | support.lenovo.com | Patch, Vendor Advisory |
| Lenovo ThinkServer System Manager CVE-2015-3324 Certificate Validation Security Bypass Vulnerability | BID | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.