PT-2015-6149 · Lenovo · Lenovo Thinkserver Rd650+3
Publicado
2015-04-16
·
Atualizado
2017-01-18
·
CVE-2015-3322
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers versions prior to 1.26.0
Description
The issue concerns the use of weak encryption to store user and administrator BIOS passwords. This weakness allows attackers to decrypt the passwords, potentially leading to unauthorized access. The exact vectors used for the decryption are not specified.
Recommendations
For versions prior to 1.26.0, update to version 1.26.0 or later to resolve the issue with weak encryption of BIOS passwords.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Lenovo Thinkserver Rd350
Lenovo Thinkserver Rd450
Lenovo Thinkserver Rd550
Lenovo Thinkserver Rd650