8.2

CVE-2017-3752

An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaws may result in attackers being able to erase or alter the routing tables of one or many routers, switches, or other devices that support OSPF within a routing domain.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ 1g L2-7 Slb Version <= 21.0.24.0
   Ibm ≫ Flex System Version -
Ibm ≫ Virtual Fabric 10gb Version <= 7.8.12.0
   Ibm ≫ Bladecenter Version -
Ibm ≫ En2092 1gb Firmware Version <= 7.8.16.0
   Ibm ≫ Flex System Version -
Ibm ≫ Fabric Cn4093 10gb Firmware Version <= 7.8.16.0
   Ibm ≫ Flex System Version -
Ibm ≫ G8052 Firmware Version <= 7.9.19.0
   Ibm ≫ Rackswitch Version -
Ibm ≫ G8124 Firmware Version <= 7.11.9.0
   Ibm ≫ Rackswitch Version -
Ibm ≫ G8124e Firmware Version <= 7.11.9.0
   Ibm ≫ Rackswitch Version -
Ibm ≫ G8264 Firmware Version <= 7.9.19.0
   Ibm ≫ Rackswitch Version -
Ibm ≫ G8264cs Firmware Version <= 7.8.16.0
   Ibm ≫ Rackswitch Version -
Ibm ≫ G8264t Firmware Version <= 7.9.19.0
   Ibm ≫ Rackswitch Version -
Ibm ≫ G8316 Firmware Version <= 7.9.19.0
   Ibm ≫ Rackswitch Version -
Ibm ≫ G8332 Firmware Version <= 7.7.25.0
   Ibm ≫ Rackswitch Version -
Lenovo ≫ Fabric Cn4093 10gb Firmware Version <= 8.4.3.0
   Lenovo ≫ Flex System Version -
Lenovo ≫ Fabric En4093r 10gb Firmware Version <= 8.4.3.0
   Lenovo ≫ Flex System Version -
Lenovo ≫ Si4091 Firmware Version <= 8.4.3.0
   Lenovo ≫ Flex System Version -
Lenovo ≫ G8052 Firmware Version <= 8.4.3.0
   Lenovo ≫ Rackswitch Version -
Lenovo ≫ G8124e Firmware Version <= 8.4.3.0
   Lenovo ≫ Rackswitch Version -
Lenovo ≫ G8264 Firmware Version <= 8.4.3.0
   Lenovo ≫ Rackswitch Version -
Lenovo ≫ G8264cs Firmware Version <= 8.4.3.0
   Lenovo ≫ Rackswitch Version -
Lenovo ≫ G8272 Firmware Version <= 8.4.3.0
   Lenovo ≫ Rackswitch Version -
Lenovo ≫ G8296 Firmware Version <= 8.4.3.0
   Lenovo ≫ Rackswitch Version -
Lenovo ≫ G8332 Firmware Version <= 8.4.3.0
   Lenovo ≫ Rackswitch Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.44% 0.348
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.2 1.6 6
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H
NIST 4.3 5.5 4.9
AV:A/AC:M/Au:N/C:N/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.securityfocus.com/bid/99995
Third Party Advisory
VDB Entry
https://support.lenovo.com/us/en/product_security/LEN-14078
Vendor Advisory