Описание
In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console, Telnet, SSH, and Web interfaces. This bypass mechanism can be accessed when performing local authentication under specific circumstances. If exploited, admin-level access to the switch is granted.
Ссылки
- Third Party Advisory
- MitigationPatchVendor Advisory
- Third Party Advisory
- MitigationPatchVendor Advisory
Уязвимые конфигурации
Одновременно
Одно из
Одновременно
Одно из
EPSS
7 High
CVSS3
6.2 Medium
CVSS2
Дефекты
Связанные уязвимости
In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console, Telnet, SSH, and Web interfaces. This bypass mechanism can be accessed when performing local authentication under specific circumstances. If exploited, admin-level access to the switch is granted.
EPSS
7 High
CVSS3
6.2 Medium
CVSS2