// For flags

CVE-2017-3765

 

Severity Score

7.0
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console, Telnet, SSH, and Web interfaces. This bypass mechanism can be accessed when performing local authentication under specific circumstances. If exploited, admin-level access to the switch is granted.

En Enterprise Networking Operating System (ENOS) en productos Lenovo, IBM RackSwitch y BladeCenter, se descubrió una omisión de autenticación conocida como "HP Backdoor" durante una auditaría de seguridad de Lenovo en las interfaces de la consola de serie, Telnet, SSH y Web. Se puede acceder al mecanismo de omisión cuando se realiza una autenticación local bajo ciertas circunstancias. Si se explota, se concede el acceso a nivel de administrador al switch.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
High
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-12-16 CVE Reserved
  • 2018-01-10 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Lenovo
Search vendor "Lenovo"
Flex System Fabric Cn4093 10gb Converged Scalable Switch
Search vendor "Lenovo" for product "Flex System Fabric Cn4093 10gb Converged Scalable Switch"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Lenovo
Search vendor "Lenovo"
Flex System Fabric En4093r 10gb Scalable Switch
Search vendor "Lenovo" for product "Flex System Fabric En4093r 10gb Scalable Switch"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Lenovo
Search vendor "Lenovo"
Flex System Fabric Si4093 10gb System Interconnect Module
Search vendor "Lenovo" for product "Flex System Fabric Si4093 10gb System Interconnect Module"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Lenovo
Search vendor "Lenovo"
Flex System Si4091 System Interconnect Module
Search vendor "Lenovo" for product "Flex System Si4091 System Interconnect Module"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Lenovo
Search vendor "Lenovo"
Rackswitch G7028
Search vendor "Lenovo" for product "Rackswitch G7028"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Lenovo
Search vendor "Lenovo"
Rackswitch G7052
Search vendor "Lenovo" for product "Rackswitch G7052"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Lenovo
Search vendor "Lenovo"
Rackswitch G8052
Search vendor "Lenovo" for product "Rackswitch G8052"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Lenovo
Search vendor "Lenovo"
Rackswitch G8124e
Search vendor "Lenovo" for product "Rackswitch G8124e"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Lenovo
Search vendor "Lenovo"
Rackswitch G8264
Search vendor "Lenovo" for product "Rackswitch G8264"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Lenovo
Search vendor "Lenovo"
Rackswitch G8264cs
Search vendor "Lenovo" for product "Rackswitch G8264cs"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Lenovo
Search vendor "Lenovo"
Rackswitch G8272
Search vendor "Lenovo" for product "Rackswitch G8272"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Lenovo
Search vendor "Lenovo"
Rackswitch G8296
Search vendor "Lenovo" for product "Rackswitch G8296"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Lenovo
Search vendor "Lenovo"
Rackswitch G8332
Search vendor "Lenovo" for product "Rackswitch G8332"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Ibm
Search vendor "Ibm"
1g L2-7 Slb Switch For Bladecenter
Search vendor "Ibm" for product "1g L2-7 Slb Switch For Bladecenter"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Ibm
Search vendor "Ibm"
Bladecenter 1:10g Uplink Ethernet Switch Module
Search vendor "Ibm" for product "Bladecenter 1:10g Uplink Ethernet Switch Module"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Ibm
Search vendor "Ibm"
Bladecenter Layer 2\/3 Copper Ethernet Switch Module
Search vendor "Ibm" for product "Bladecenter Layer 2\/3 Copper Ethernet Switch Module"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Ibm
Search vendor "Ibm"
Bladecenter Virtual Fabric 10gb Switch Module
Search vendor "Ibm" for product "Bladecenter Virtual Fabric 10gb Switch Module"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Ibm
Search vendor "Ibm"
Flex System En2092 1gb Ethernet Scalable Switch
Search vendor "Ibm" for product "Flex System En2092 1gb Ethernet Scalable Switch"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Ibm
Search vendor "Ibm"
Flex System Fabric Cn4093 10gb Converged Scalable Switch
Search vendor "Ibm" for product "Flex System Fabric Cn4093 10gb Converged Scalable Switch"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Ibm
Search vendor "Ibm"
Flex System Fabric En4093\/en4093r 10gb Scalable Switch
Search vendor "Ibm" for product "Flex System Fabric En4093\/en4093r 10gb Scalable Switch"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Ibm
Search vendor "Ibm"
Flex System Fabric Si4093 10gb System Interconnect Module
Search vendor "Ibm" for product "Flex System Fabric Si4093 10gb System Interconnect Module"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Ibm
Search vendor "Ibm"
Rackswitch G8052
Search vendor "Ibm" for product "Rackswitch G8052"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Ibm
Search vendor "Ibm"
Rackswitch G8124
Search vendor "Ibm" for product "Rackswitch G8124"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Ibm
Search vendor "Ibm"
Rackswitch G8124e
Search vendor "Ibm" for product "Rackswitch G8124e"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Ibm
Search vendor "Ibm"
Rackswitch G8264
Search vendor "Ibm" for product "Rackswitch G8264"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Ibm
Search vendor "Ibm"
Rackswitch G8264cs
Search vendor "Ibm" for product "Rackswitch G8264cs"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Ibm
Search vendor "Ibm"
Rackswitch G8264t
Search vendor "Ibm" for product "Rackswitch G8264t"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Ibm
Search vendor "Ibm"
Rackswitch G8316
Search vendor "Ibm" for product "Rackswitch G8316"
--
Safe
Lenovo
Search vendor "Lenovo"
Enterprise Network Operating System
Search vendor "Lenovo" for product "Enterprise Network Operating System"
< 8.4.6.0
Search vendor "Lenovo" for product "Enterprise Network Operating System" and version " < 8.4.6.0"
-
Affected
in Ibm
Search vendor "Ibm"
Rackswitch G8332
Search vendor "Ibm" for product "Rackswitch G8332"
--
Safe