Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-3324


The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "encrypted remote KVM session," which allows man-in-the-middle attackers to spoof servers.


Published

2015-04-16T23:59:05.540

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-310

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System lenovo thinkserver_system_manager_baseboard_management_controller_firmware 118.71532 Yes
Hardware lenovo thinkserver_rd350 - No
Hardware lenovo thinkserver_rd450 - No
Hardware lenovo thinkserver_rd550 - No
Hardware lenovo thinkserver_rd650 - No
Hardware lenovo thinkserver_td350 - No

References