CVE-2015-3322: Lenovo Thinkserver RD350

Medium severity, CVSS 5.0. EPSS: 0.7% chance of exploitation in the next 30 days.

Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passwords, which allows attackers to decrypt the passwords via unspecified vectors.

Affected products

  • Lenovo Thinkserver RD350
  • Lenovo Thinkserver RD350 Firmware: up to and including 1.25.0
  • Lenovo Thinkserver RD450
  • Lenovo Thinkserver RD450 Firmware: up to and including 1.25.0
  • Lenovo Thinkserver RD550
  • Lenovo Thinkserver RD550 Firmware: up to and including 1.25.0
  • Lenovo Thinkserver RD650
  • Lenovo Thinkserver RD650 Firmware: up to and including 1.25.0
  • Lenovo Thinkserver TD350
  • Lenovo Thinkserver TD350 Firmware: up to and including 1.25.0

Published 2015-04-16. Last modified 2026-06-17.