CVE-2017-3765
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
10/01/2018
Last modified:
06/02/2018
Description
In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console, Telnet, SSH, and Web interfaces. This bypass mechanism can be accessed when performing local authentication under specific circumstances. If exploited, admin-level access to the switch is granted.
Impact
Base Score 3.x
7.00
Severity 3.x
HIGH
Base Score 2.0
6.20
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:lenovo:enterprise_network_operating_system:*:*:*:*:*:*:*:* | 8.4.6.0 (excluding) | |
cpe:2.3:h:lenovo:flex_system_fabric_cn4093_10gb_converged_scalable_switch:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:lenovo:flex_system_fabric_en4093r_10gb_scalable_switch:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:lenovo:flex_system_fabric_si4093_10gb_system_interconnect_module:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:lenovo:flex_system_si4091_system_interconnect_module:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:lenovo:rackswitch_g7028:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:lenovo:rackswitch_g7052:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:lenovo:rackswitch_g8052:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:lenovo:rackswitch_g8124e:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:lenovo:rackswitch_g8264:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:lenovo:rackswitch_g8264cs:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:lenovo:rackswitch_g8272:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:lenovo:rackswitch_g8296:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:lenovo:rackswitch_g8332:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:lenovo:enterprise_network_operating_system:*:*:*:*:*:*:*:* | 8.4.6.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page