Attackers with physical access to Lenovo RackSwitch may be able to load unsigned firmware.

Source: Internet
Author: User
Tags lenovo
Lenovo security announcement:LEN-7805

 

Potential impact:Attackers with physical access permissions may be able to load unsigned firmware.

 

Severity :Medium

 

Impact scope:Lenovo

 

Abstract description:

 

During the internal test, Lenovo found a vulnerability in some Lenovo RackSwitch Ethernet switches, which manifested, attackers with physical access to the USB interface may be able to bypass internal checks and upload unsigned firmware when the switch is running at a specific firmware level. In addition to the specially crafted firmware image, attackers also need a valid management account to log on to the vSwitch, or they need to shut down the vSwitch and then start it offline to successfully exploit this vulnerability.


Solution:

Measures should be taken for self-protection:

 

Lenovo recommends that you download the software provided in the following link to update the switch firmware to the latest version. Users who cannot install the patch should restrict the physical access permissions of the switch and monitor and investigate the unexpected restart of the switch.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.