CVE-2015-3323

The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 allows remote attackers to cause a denial of service (web interface crash) via a malformed HTTP request during authentication.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:lenovo:thinkserver_system_manager_baseboard_management_controller_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:lenovo:thinkserver_rd350:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd450:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd550:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_rd650:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkserver_td350:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:29

Type Values Removed Values Added
References () http://support.lenovo.com/us/en/product_security/tsm_weak_pw - Vendor Advisory () http://support.lenovo.com/us/en/product_security/tsm_weak_pw - Vendor Advisory
References () http://www.securityfocus.com/bid/74197 - () http://www.securityfocus.com/bid/74197 -

Information

Published : 2015-04-16 23:59

Updated : 2024-11-21 02:29


NVD link : CVE-2015-3323

Mitre link : CVE-2015-3323

CVE.ORG link : CVE-2015-3323


JSON object : View

Products Affected

lenovo

  • thinkserver_rd350
  • thinkserver_system_manager_baseboard_management_controller_firmware
  • thinkserver_rd550
  • thinkserver_rd450
  • thinkserver_rd650
  • thinkserver_td350
CWE
CWE-20

Improper Input Validation