CVE-2017-3752

UnknownEPSS 0.44%

Last modified

CVE-2017-3752 is a vulnerability of currently unknown severity. An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaws may result in attackers being able to erase or alter the routing tables of one or many routers, switches, or other devices that support OSPF within a routing domain.. EPSS estimates a 0.44% chance of exploitation in the next 30 days.

Description

An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaws may result in attackers being able to erase or alter the routing tables of one or many routers, switches, or other devices that support OSPF within a routing domain.

Metrics

EPSS Probability
0.44%

35.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Ibm1g L2-7 Slb<= 21.0.24.0
Ibm1\<= 7.4.16.0
IbmLayer 2\/3 Copper Firmware<= 5.3.10.0
IbmVirtual Fabric 10gb<= 7.8.12.0
IbmEn2092 1gb Firmware<= 7.8.16.0
IbmFabric Cn4093 10gb Firmware<= 7.8.16.0
IbmFabric En4093\/En4093r 10gb Firmware<= 7.8.16.0
IbmG8052 Firmware<= 7.9.19.0
IbmG8124 Firmware<= 7.11.9.0
IbmG8124e Firmware<= 7.11.9.0
IbmG8264 Firmware<= 7.9.19.0
IbmG8264cs Firmware<= 7.8.16.0
IbmG8264t Firmware<= 7.9.19.0
IbmG8316 Firmware<= 7.9.19.0
IbmG8332 Firmware<= 7.7.25.0
LenovoFabric Cn4093 10gb Firmware<= 8.4.3.0
LenovoFabric En4093r 10gb Firmware<= 8.4.3.0
LenovoSi4091 Firmware<= 8.4.3.0
LenovoG8052 Firmware<= 8.4.3.0
LenovoG8124e Firmware<= 8.4.3.0
LenovoG8264 Firmware<= 8.4.3.0
LenovoG8264cs Firmware<= 8.4.3.0
LenovoG8272 Firmware<= 8.4.3.0
LenovoG8296 Firmware<= 8.4.3.0
LenovoG8332 Firmware<= 8.4.3.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-3752?
An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaws may result in attackers being able to erase or alter the routing tables of one or many routers, switches, or other devices that support OSPF within a routing domain.
How severe is CVE-2017-3752?
Severity scoring for CVE-2017-3752 is pending analysis. The EPSS model estimates a 0.44% probability of exploitation in the next 30 days.
How do I fix CVE-2017-3752?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-3752?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST