First published: Wed Aug 09 2017(Updated: )
An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaws may result in attackers being able to erase or alter the routing tables of one or many routers, switches, or other devices that support OSPF within a routing domain.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM BladeCenter 1G L2-7 SLB | <=21.0.24.0 | |
IBM Flex System | ||
IBM 1 | <=7.4.16.0 | |
IBM BladeCenter | ||
IBM Layer 2/3 Copper Firmware | <=5.3.10.0 | |
Ibm Virtual Fabric 10gb | <=7.8.12.0 | |
IBM EN2092 1GB Firmware | <=7.8.16.0 | |
Lenovo Fabric Cn4093 10gb Firmware | <=7.8.16.0 | |
IBM Fabric EN4093/EN4093R 10Gb Firmware | <=7.8.16.0 | |
Lenovo G8052 Firmware | <=7.9.19.0 | |
IBM RackSwitch | ||
Ibm G8124 Firmware | <=7.11.9.0 | |
Lenovo G8124e Firmware | <=7.11.9.0 | |
Lenovo G8264cs Firmware | <=7.9.19.0 | |
Lenovo G8264cs Firmware | <=7.8.16.0 | |
IBM G8264T Firmware | <=7.9.19.0 | |
IBM G8316 Firmware | <=7.9.19.0 | |
Lenovo G8332 Firmware | <=7.7.25.0 | |
Lenovo Fabric Cn4093 10gb Firmware | <=8.4.3.0 | |
Lenovo Flex System | ||
Lenovo Fabric En4093r 10gb Firmware | <=8.4.3.0 | |
Lenovo Si4091 Firmware | <=8.4.3.0 | |
Lenovo G8052 Firmware | <=8.4.3.0 | |
Lenovo RackSwitch | ||
Lenovo G8124e Firmware | <=8.4.3.0 | |
Lenovo G8264cs Firmware | <=8.4.3.0 | |
Lenovo G8264cs Firmware | <=8.4.3.0 | |
Lenovo G8272 Firmware | <=8.4.3.0 | |
Lenovo G8296 Firmware | <=8.4.3.0 | |
Lenovo G8332 Firmware | <=8.4.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3752 has been classified as a high severity vulnerability due to its potential impact on routing protocols.
To fix CVE-2017-3752, it is essential to update the affected Lenovo switch firmware to the latest version provided by Lenovo.
CVE-2017-3752 affects various Lenovo and IBM switch models, especially those utilizing OSPF routing protocol in specific firmware versions.
Exploitation of CVE-2017-3752 may allow attackers to erase or alter the routing tables of affected Lenovo switches.
Yes, CVE-2017-3752 is considered to be exploitable remotely if specific conditions are met, making it critical to apply patches.