CVE-2015-3322: Weak Encryption
Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passwords, which allows attackers to decrypt the passwords via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3322?
CVE-2015-3322 is considered to have a high severity due to the use of weak encryption for sensitive BIOS passwords.
How do I fix CVE-2015-3322?
To mitigate CVE-2015-3322, users should update their Lenovo ThinkServer firmware to version 1.26.0 or later.
What systems are affected by CVE-2015-3322?
CVE-2015-3322 affects Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers running firmware versions up to 1.25.0.
What kind of passwords are exposed in CVE-2015-3322?
CVE-2015-3322 exposes both user and administrator BIOS passwords, allowing attackers to decrypt them.
How can attackers exploit CVE-2015-3322?
Attackers can exploit CVE-2015-3322 through unspecified vectors to decrypt the weakly stored BIOS passwords.