First published: Thu Apr 16 2015(Updated: )
The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 allows remote attackers to cause a denial of service (web interface crash) via a malformed HTTP request during authentication.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Thinkserver System Manager Baseboard Management Controller Firmware | <=118.71532. | |
Lenovo ThinkServer RD350 | ||
Lenovo ThinkServer RD450 | ||
Lenovo ThinkServer RD550 | ||
Lenovo ThinkServer RD650 | ||
Lenovo ThinkServer TD350 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3323 is categorized as a denial of service vulnerability impacting the web interface of the ThinkServer System Manager.
To remediate CVE-2015-3323, update the ThinkServer System Manager Baseboard Management Controller firmware to version 1.27.73476 or later.
CVE-2015-3323 affects the ThinkServer RD350, RD450, RD550, RD650, and TD350 models running the vulnerable firmware versions.
Yes, CVE-2015-3323 can be exploited remotely through a malformed HTTP request during the authentication process.
Exploitation of CVE-2015-3323 could lead to a denial of service, causing the web interface of the affected device to crash.