Podatność CVE-2017-3752


Publikacja: 2017-08-09

Opis:
An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaws may result in attackers being able to erase or alter the routing tables of one or many routers, switches, or other devices that support OSPF within a routing domain.

Producent: Lenovo
Produkt: G8272 firmware 
Wersje: 8.4.3.0;
Produkt: G8332 firmware 
Wersje: 8.4.3.0;
Produkt: Fabric en4093r 10gb firmware 
Wersje: 8.4.3.0;
Produkt: G8296 firmware 
Wersje: 8.4.3.0;
Produkt: G8052 firmware 
Wersje: 8.4.3.0;
Produkt: G8264cs firmware 
Wersje: 8.4.3.0;
Produkt: Fabric cn4093 10gb firmware 
Wersje: 8.4.3.0;
Produkt: G8124e firmware 
Wersje: 8.4.3.0;
Produkt: G8264 firmware 
Wersje: 8.4.3.0;
Produkt: Si4091 firmware 
Wersje: 8.4.3.0;
Producent: IBM
Produkt: G8264t firmware 
Wersje: 7.9.19.0;
Produkt: G8264 firmware 
Wersje: 7.9.19.0;
Produkt: G8052 firmware 
Wersje: 7.9.19.0;
Produkt: G8316 firmware 
Wersje: 7.9.19.0;
Produkt: Fabric cn4093 10gb firmware 
Wersje: 7.8.16.0;
Produkt: En2092 1gb firmware 
Wersje: 7.8.16.0;
Produkt: Fabric en4093/en4093r 10gb firmware 
Wersje: 7.8.16.0;
Produkt: G8264cs firmware 
Wersje: 7.8.16.0;
Produkt: Virtual fabric 10gb 
Wersje: 7.8.12.0;
Produkt: G8332 firmware 
Wersje: 7.7.25.0;
Produkt: G8124 firmware 
Wersje: 7.11.9.0;
Produkt: G8124e firmware 
Wersje: 7.11.9.0;
Produkt: Layer 2/3 copper firmware 
Wersje: 5.3.10.0;
Produkt: 1g l2-7 slb 
Wersje: 21.0.24.0;
Produkt: 1 
Wersje: 10g_firmware;

CVSS2 => (AV:A/AC:M/Au:N/C:N/I:P/A:P)

Ogólna skala CVSS
Znaczenie
Łatwość wykorzystania
4.3/10
4.9/10
5.5/10
Wymagany dostęp
Złożoność ataku
Autoryzacja
Sieć lokalna
Średnia
Nie wymagana
Wpływ na poufność
Wpływ na integralność
Wpływ na dostępność
Brak
Częściowy
Częściowy

 Referencje:
http://www.securityfocus.com/bid/99995
https://support.lenovo.com/us/en/product_security/LEN-14078

Podobne CVE
CVE-2019-4265
IBM Maximo Anywhere 7.6.0, 7.6.1, 7.6.2, and 7.6.3 does not have device root detection which could result in an attacker gaining sensitive information about the device. IBM X-Force ID: 160198.
CVE-2019-4558
A security vulnerability has been identified in all levels of IBM Spectrum Scale V5.0.0.0 through V5.0.3.2 and IBM Spectrum Scale V4.2.0.0 through V4.2.3.17 that could allow a local attacker to obtain root privilege by injecting parameters into setui...
CVE-2019-4512
IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554.
CVE-2019-4564
IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden...
CVE-2019-4514
IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0, and 3.0.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 165136.
CVE-2019-4227
IBM MQ 8.0.0.4 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 AMQP Listeners could allow an unauthorized user to conduct a session fixation attack due to clients not being disconnected as they should. IBM X-Force ID: 159352.
CVE-2019-4441
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 163177.
CVE-2019-4422
IBM Security Guardium 9.0, 9.5, and 10.6 are vulnerable to a privilege escalation which could allow an authenticated user to change the accessmgr password. IBM X-Force ID: 162768.

Copyright 2019, cxsecurity.com

 

Back to Top