HIGH · 8.2

CVE-2017-3752

An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaw...

Vulnerability Description

An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaws may result in attackers being able to erase or alter the routing tables of one or many routers, switches, or other devices that support OSPF within a routing domain.

CVSS Score

8.2

HIGH

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
LOW
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Ibm1G L2-7 Slb<= 21.0.24.0
IbmFlex System-
Ibm1\<= 7.4.16.0, 10g_firmware
IbmBladecenter-
IbmLayer 2\/3 Copper Firmware<= 5.3.10.0
IbmVirtual Fabric 10Gb<= 7.8.12.0
IbmEn2092 1Gb Firmware<= 7.8.16.0
IbmFabric Cn4093 10Gb Firmware<= 7.8.16.0
IbmFabric En4093\/En4093R 10Gb Firmware<= 7.8.16.0
IbmG8052 Firmware<= 7.9.19.0
IbmRackswitch-
IbmG8124 Firmware<= 7.11.9.0
IbmG8124E Firmware<= 7.11.9.0
IbmG8264 Firmware<= 7.9.19.0
IbmG8264Cs Firmware<= 7.8.16.0
IbmG8264T Firmware<= 7.9.19.0
IbmG8316 Firmware<= 7.9.19.0
IbmG8332 Firmware<= 7.7.25.0
LenovoFabric Cn4093 10Gb Firmware<= 8.4.3.0
LenovoFlex System-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-3752?

CVE-2017-3752 is a vulnerability with a CVSS score of 8.2 (HIGH). An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaw...

How severe is CVE-2017-3752?

CVE-2017-3752 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-3752?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm 1G L2-7 Slb, Ibm Flex System, Ibm 1\, Ibm Bladecenter, Ibm Layer 2\/3 Copper Firmware.