漏洞信息详情
多款Lenovo和IBM Networking Switches 安全漏洞
漏洞简介
Lenovo Flex System Fabric CN4093 10Gb Converged Scalable Switch等都是中国联想(Lenovo)公司的交换机设备。IBM 1G L2-7 SLB switch for Bladecenter等都是美国IBM公司的交换机设备。Open Shortest Path First(OSPF)routing protocol是使用在其中的一个链路状态(开放最短路优先)路由协议。
多款Lenovo和IBM Networking Switches中的Open Shortest Path First (OSPF) routing protocol实现存在安全漏洞。攻击者可利用该漏洞删除和更改路由选择表。以下产品受到影响:IBM 1G L2-7 SLB switch for Bladecenter;IBM Bladecenter 1:10G Uplink Ethernet switch Module;IBM BladeCenter Layer 2/3 Copper Ethernet Switch Module;IBM BladeCenter Virtual Fabric 10Gb Switch Module;IBM Flex System EN2092 1Gb Ethernet Scalable Switch;IBM Flex System? Fabric CN4093 10Gb Converged Scalable Switch;IBM Flex System? Fabric EN4093/EN4093R 10Gb Scalable Switch;IBM RackSwitch G8052;IBM RackSwitch G8124;IBM RackSwitch G8124E;IBM RackSwitch G8264;IBM RackSwitch G8264CS;IBM RackSwitch G8264T;IBM RackSwitch G8316;IBM Rackswitch G8332;Lenovo Flex System Fabric CN4093 10Gb Converged Scalable Switch;Lenovo Flex System Fabric EN4093R 10Gb Scalable Switch;Lenovo Flex System SI4091 System Interconnect Module;Lenovo RackSwitch G8052;Lenovo RackSwitch G8124E (ThinkAgile CX2200);Lenovo RackSwitch G8264;Lenovo RackSwitch G8264CS;Lenovo RackSwitch G8272 (ThinkAgile CX4200/CX4600);Lenovo RackSwitch G8296;Lenovo RackSwitch G8332。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://support.lenovo.com/us/zh/product_security/len-14078
参考网址
来源:BID
链接:http://www.securityfocus.com/bid/99995
来源:CONFIRM
链接:https://support.lenovo.com/us/en/product_security/LEN-14078
受影响实体
- Lenovo G8124e_firmware:8.4.3.0<!--2000-1-1-->
- Lenovo G8264_firmware:8.4.3.0<!--2000-1-1-->
- Lenovo G8332_firmware:8.4.3.0<!--2000-1-1-->
- Lenovo G8272_firmware:8.4.3.0<!--2000-1-1-->
- Lenovo G8296_firmware:8.4.3.0<!--2000-1-1-->
补丁
- 多款Lenovo和IBM Networking Switches 安全漏洞的修复措施<!--2017-8-28-->
还没有评论,来说两句吧...