In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console, Telnet, SSH, and Web interfaces. This bypass mechanism can be accessed when performing local authentication under specific circumstances. If exploited, admin-level access to the switch is granted.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Ibm
Subscribe
|
1g L2-7 Slb Switch For Bladecenter
Subscribe
Bladecenter 1\
Subscribe
Bladecenter Layer 2\/3 Copper Ethernet Switch Module
Subscribe
Bladecenter Virtual Fabric 10gb Switch Module
Subscribe
Flex System En2092 1gb Ethernet Scalable Switch
Subscribe
Flex System Fabric Cn4093 10gb Converged Scalable Switch
Subscribe
Flex System Fabric En4093\/en4093r 10gb Scalable Switch
Subscribe
Flex System Fabric Si4093 10gb System Interconnect Module
Subscribe
Rackswitch G8052
Subscribe
Rackswitch G8124
Subscribe
Rackswitch G8124e
Subscribe
Rackswitch G8264
Subscribe
Rackswitch G8264cs
Subscribe
Rackswitch G8264t
Subscribe
Rackswitch G8316
Subscribe
Rackswitch G8332
Subscribe
|
|
Lenovo
Subscribe
|
Enterprise Network Operating System
Subscribe
Flex System Fabric Cn4093 10gb Converged Scalable Switch
Subscribe
Flex System Fabric En4093r 10gb Scalable Switch
Subscribe
Flex System Fabric Si4093 10gb System Interconnect Module
Subscribe
Flex System Si4091 System Interconnect Module
Subscribe
Rackswitch G7028
Subscribe
Rackswitch G7052
Subscribe
Rackswitch G8052
Subscribe
Rackswitch G8124e
Subscribe
Rackswitch G8264
Subscribe
Rackswitch G8264cs
Subscribe
Rackswitch G8272
Subscribe
Rackswitch G8296
Subscribe
Rackswitch G8332
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-12882 | In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console, Telnet, SSH, and Web interfaces. This bypass mechanism can be accessed when performing local authentication under specific circumstances. If exploited, admin-level access to the switch is granted. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-09-17T01:10:39.100Z
Reserved: 2016-12-16T00:00:00.000Z
Link: CVE-2017-3765
No data.
Status : Modified
Published: 2018-01-10T18:29:01.383
Modified: 2024-11-21T03:26:05.847
Link: CVE-2017-3765
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD