Lenovo security announcement:LEN-7805
Potential impact:Attackers with physical access permissions may be able to load unsigned firmware.
Severity
:Medium
Impact scope:Lenovo
Abstract description:
During the internal test, Lenovo found a vulnerability in some Lenovo RackSwitch Ethernet switches, which manifested, attackers with physical access to the USB interface may be able to bypass internal checks and upload unsigned firmware when the switch is running at a specific firmware level. In addition to the specially crafted firmware image, attackers also need a valid management account to log on to the vSwitch, or they need to shut down the vSwitch and then start it offline to successfully exploit this vulnerability.
Solution:
Measures should be taken for self-protection:
Lenovo recommends that you download the software provided in the following link to update the switch firmware to the latest version. Users who cannot install the patch should restrict the physical access permissions of the switch and monitor and investigate the unexpected restart of the switch.