Man-in-the-Middle Vulnerability in ThinkServer System Manager by Lenovo
CVE-2015-3324
Currently unrated
Key Information:
- Vendor
- Lenovo
- Vendor
- CVE Published:
- 16 April 2015
Summary
The ThinkServer System Manager (TSM) Baseboard Management Controller prior to firmware version 1.27.73476 exposes systems to man-in-the-middle attacks by failing to validate server certificates during encrypted remote KVM sessions. This vulnerability allows attackers to potentially spoof server communications, compromising the integrity and confidentiality of data during remote management operations.
References
Timeline
Vulnerability published
Vulnerability Reserved