MEDIUM · 4.3

CVE-2015-3324

The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "e...

Vulnerability Description

The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "encrypted remote KVM session," which allows man-in-the-middle attackers to spoof servers.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
LenovoThinkserver System Manager Baseboard Management Controller Firmware118.71532
LenovoThinkserver Rd350-
LenovoThinkserver Rd450-
LenovoThinkserver Rd550-
LenovoThinkserver Rd650-
LenovoThinkserver Td350-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-3324?

CVE-2015-3324 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "e...

How severe is CVE-2015-3324?

CVE-2015-3324 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-3324?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Thinkserver System Manager Baseboard Management Controller Firmware, Lenovo Thinkserver Rd350, Lenovo Thinkserver Rd450, Lenovo Thinkserver Rd550, Lenovo Thinkserver Rd650.