SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-3322

Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passwords, which allows attackers to decrypt the passwords via unspecified vectors.

MEDIUM 5.0EPSS 0.71%

Does this matter?

Lower severity and a low EPSS score (0.71%). Track it; it rarely justifies an emergency change on its own.

Description

Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passwords, which allows attackers to decrypt the passwords via unspecified vectors.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
0.71% probability · 52th percentile
CISA KEV
Not listed
Weakness
CWE-310
Affected
lenovo/thinkserver rd650 firmware · lenovo/thinkserver rd650 · lenovo/thinkserver td350 firmware · lenovo/thinkserver td350 · lenovo/thinkserver rd350 firmware · lenovo/thinkserver rd350 · lenovo/thinkserver rd550 firmware · lenovo/thinkserver rd550 · lenovo/thinkserver rd450 firmware · lenovo/thinkserver rd450
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.