VulnerabilityModified
CVE-2015-3322
Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passwords, which allows attackers to decrypt the passwords via unspecified vectors.
MEDIUM 5.0EPSS 0.71%
Does this matter?
Lower severity and a low EPSS score (0.71%). Track it; it rarely justifies an emergency change on its own.
Description
Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passwords, which allows attackers to decrypt the passwords via unspecified vectors.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.71% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- lenovo/thinkserver rd650 firmware · lenovo/thinkserver rd650 · lenovo/thinkserver td350 firmware · lenovo/thinkserver td350 · lenovo/thinkserver rd350 firmware · lenovo/thinkserver rd350 · lenovo/thinkserver rd550 firmware · lenovo/thinkserver rd550 · lenovo/thinkserver rd450 firmware · lenovo/thinkserver rd450
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/74198Third Party Advisory, VDB Entry
- https://support.lenovo.com/us/en/product_security/ts_bios_pwPatch, Vendor Advisory
- http://www.securityfocus.com/bid/74198Third Party Advisory, VDB Entry
- https://support.lenovo.com/us/en/product_security/ts_bios_pwPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.