CVE-2017-3752
Summary
| CVE | CVE-2017-3752 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-09 21:29:00 UTC |
| Updated | 2017-08-30 17:50:00 UTC |
| Description | An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaws may result in attackers being able to erase or alter the routing tables of one or many routers, switches, or other devices that support OSPF within a routing domain. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Ibm | 1 | 10g_firmware | All | All | All |
| Operating System | Ibm | 1g L2-7 Slb | All | All | All | All |
| Operating System | Ibm | 1 | 10g_firmware | All | All | All |
| Hardware | Ibm | Bladecenter | - | All | All | All |
| Hardware | Ibm | Bladecenter | - | All | All | All |
| Operating System | Ibm | En2092 1gb Firmware | All | All | All | All |
| Operating System | Ibm | Fabric Cn4093 10gb Firmware | All | All | All | All |
| Operating System | Ibm | Fabric En4093/en4093r 10gb Firmware | All | All | All | All |
| Operating System | Ibm | Fabric En4093/en4093r 10gb Firmware | All | All | All | All |
| Hardware | Ibm | Flex System | - | All | All | All |
| Hardware | Ibm | Flex System | - | All | All | All |
| Operating System | Ibm | G8052 Firmware | All | All | All | All |
| Operating System | Ibm | G8124e Firmware | All | All | All | All |
| Operating System | Ibm | G8124 Firmware | All | All | All | All |
| Operating System | Ibm | G8264cs Firmware | All | All | All | All |
| Operating System | Ibm | G8264t Firmware | All | All | All | All |
| Operating System | Ibm | G8264 Firmware | All | All | All | All |
| Operating System | Ibm | G8316 Firmware | All | All | All | All |
| Operating System | Ibm | G8332 Firmware | All | All | All | All |
| Operating System | Ibm | Layer 2/3 Copper Firmware | All | All | All | All |
| Operating System | Ibm | Layer 2/3 Copper Firmware | All | All | All | All |
| Hardware | Ibm | Rackswitch | - | All | All | All |
| Hardware | Ibm | Rackswitch | - | All | All | All |
| Operating System | Ibm | Virtual Fabric 10gb | All | All | All | All |
| Operating System | Lenovo | Fabric Cn4093 10gb Firmware | All | All | All | All |
| Operating System | Lenovo | Fabric En4093r 10gb Firmware | All | All | All | All |
| Hardware | Lenovo | Flex System | - | All | All | All |
| Hardware | Lenovo | Flex System | - | All | All | All |
| Operating System | Lenovo | G8052 Firmware | All | All | All | All |
| Operating System | Lenovo | G8124e Firmware | All | All | All | All |
| Operating System | Lenovo | G8264cs Firmware | All | All | All | All |
| Operating System | Lenovo | G8264 Firmware | All | All | All | All |
| Operating System | Lenovo | G8272 Firmware | All | All | All | All |
| Operating System | Lenovo | G8296 Firmware | All | All | All | All |
| Operating System | Lenovo | G8332 Firmware | All | All | All | All |
| Hardware | Lenovo | Rackswitch | - | All | All | All |
| Hardware | Lenovo | Rackswitch | - | All | All | All |
| Operating System | Lenovo | Si4091 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 99995 | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Industry-wide OSPF routing vulnerability on Lenovo and IBM Networking Switches | CONFIRM | support.lenovo.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.