Man-in-the-Middle Vulnerability in ThinkServer System Manager by Lenovo
CVE-2015-3324

Currently unrated

Key Information:

Summary

The ThinkServer System Manager (TSM) Baseboard Management Controller prior to firmware version 1.27.73476 exposes systems to man-in-the-middle attacks by failing to validate server certificates during encrypted remote KVM sessions. This vulnerability allows attackers to potentially spoof server communications, compromising the integrity and confidentiality of data during remote management operations.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.