CVE-2017-3765

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
10/01/2018
Last modified:
06/02/2018

Description

In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console, Telnet, SSH, and Web interfaces. This bypass mechanism can be accessed when performing local authentication under specific circumstances. If exploited, admin-level access to the switch is granted.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lenovo:enterprise_network_operating_system:*:*:*:*:*:*:*:* 8.4.6.0 (excluding)
cpe:2.3:h:lenovo:flex_system_fabric_cn4093_10gb_converged_scalable_switch:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:flex_system_fabric_en4093r_10gb_scalable_switch:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:flex_system_fabric_si4093_10gb_system_interconnect_module:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:flex_system_si4091_system_interconnect_module:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:rackswitch_g7028:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:rackswitch_g7052:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:rackswitch_g8052:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:rackswitch_g8124e:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:rackswitch_g8264:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:rackswitch_g8264cs:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:rackswitch_g8272:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:rackswitch_g8296:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:rackswitch_g8332:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:enterprise_network_operating_system:*:*:*:*:*:*:*:* 8.4.6.0 (excluding)