Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-3324

Опубликовано: 16 апр. 2015
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "encrypted remote KVM session," which allows man-in-the-middle attackers to spoof servers.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:lenovo:thinkserver_system_manager_baseboard_management_controller_firmware:118.71532:*:*:*:*:*:*:*

Одно из

cpe:2.3:h:lenovo:thinkserver_rd350:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd450:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd550:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd650:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_td350:-:*:*:*:*:*:*:*

EPSS

Процентиль: 34%
0.00137
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-310

Связанные уязвимости

github
больше 3 лет назад

The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "encrypted remote KVM session," which allows man-in-the-middle attackers to spoof servers.

EPSS

Процентиль: 34%
0.00137
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-310