In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console, Telnet, SSH, and Web interfaces. This bypass mechanism can be accessed when performing local authentication under specific circumstances. If exploited, admin-level access to the switch is granted.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.securitytracker.com/id/1040296 | Third Party Advisory | 
| https://support.lenovo.com/us/en/product_security/LEN-16095 | Mitigation Patch Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
Configuration 2 (hide)
| AND | 
            
            
 
  | 
    
History
                    No history.
Information
                Published : 2018-01-10 18:29
Updated : 2018-02-06 14:12
NVD link : CVE-2017-3765
Mitre link : CVE-2017-3765
CVE.ORG link : CVE-2017-3765
JSON object : View
Products Affected
                ibm
- rackswitch_g8264
 - flex_system_fabric_cn4093_10gb_converged_scalable_switch
 - 1g_l2-7_slb_switch_for_bladecenter
 - flex_system_fabric_en4093\/en4093r_10gb_scalable_switch
 - rackswitch_g8332
 - bladecenter_1\
 - rackswitch_g8316
 - flex_system_fabric_si4093_10gb_system_interconnect_module
 - rackswitch_g8124
 - bladecenter_virtual_fabric_10gb_switch_module
 - rackswitch_g8264t
 - bladecenter_layer_2\/3_copper_ethernet_switch_module
 - rackswitch_g8124e
 - flex_system_en2092_1gb_ethernet_scalable_switch
 - rackswitch_g8052
 - rackswitch_g8264cs
 
lenovo
- rackswitch_g7052
 - enterprise_network_operating_system
 - rackswitch_g8124e
 - rackswitch_g8052
 - rackswitch_g8264cs
 - flex_system_fabric_en4093r_10gb_scalable_switch
 - rackswitch_g8272
 - rackswitch_g8264
 - flex_system_si4091_system_interconnect_module
 - flex_system_fabric_cn4093_10gb_converged_scalable_switch
 - rackswitch_g8332
 - flex_system_fabric_si4093_10gb_system_interconnect_module
 - rackswitch_g8296
 - rackswitch_g7028
 
CWE
                
                    
                        
                        CWE-287
                        
            Improper Authentication
