Description
In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console, Telnet, SSH, and Web interfaces. This bypass mechanism can be accessed when performing local authentication under specific circumstances. If exploited, admin-level access to the switch is granted.
Published: 2018-01-10
Score: 7.0 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2017-12882 In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console, Telnet, SSH, and Web interfaces. This bypass mechanism can be accessed when performing local authentication under specific circumstances. If exploited, admin-level access to the switch is granted.
History

No history.

Subscriptions

Ibm 1g L2-7 Slb Switch For Bladecenter Bladecenter 1\ Bladecenter Layer 2\/3 Copper Ethernet Switch Module Bladecenter Virtual Fabric 10gb Switch Module Flex System En2092 1gb Ethernet Scalable Switch Flex System Fabric Cn4093 10gb Converged Scalable Switch Flex System Fabric En4093\/en4093r 10gb Scalable Switch Flex System Fabric Si4093 10gb System Interconnect Module Rackswitch G8052 Rackswitch G8124 Rackswitch G8124e Rackswitch G8264 Rackswitch G8264cs Rackswitch G8264t Rackswitch G8316 Rackswitch G8332
Lenovo Enterprise Network Operating System Flex System Fabric Cn4093 10gb Converged Scalable Switch Flex System Fabric En4093r 10gb Scalable Switch Flex System Fabric Si4093 10gb System Interconnect Module Flex System Si4091 System Interconnect Module Rackswitch G7028 Rackswitch G7052 Rackswitch G8052 Rackswitch G8124e Rackswitch G8264 Rackswitch G8264cs Rackswitch G8272 Rackswitch G8296 Rackswitch G8332
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-09-17T01:10:39.100Z

Reserved: 2016-12-16T00:00:00.000Z

Link: CVE-2017-3765

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-01-10T18:29:01.383

Modified: 2024-11-21T03:26:05.847

Link: CVE-2017-3765

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses