Multiple vulnerabilities in Lenovo Networking Switches



Published: 2022-03-23
Risk High
Patch available YES
Number of vulnerabilities 2
CVE-ID CVE-2021-27796
CVE-2021-27797
CWE-ID CWE-200
CWE-798
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Lenovo ThinkSystem DB800D FC Switch
Hardware solutions / Routers & switches, VoIP, GSM, etc

Lenovo ThinkSystem DB720S FC Switch
Hardware solutions / Routers & switches, VoIP, GSM, etc

Lenovo ThinkSystem DB630S FC Switch
Hardware solutions / Routers & switches, VoIP, GSM, etc

Lenovo ThinkSystem DB620S FC Switch
Hardware solutions / Routers & switches, VoIP, GSM, etc

Lenovo ThinkSystem DB610S FC Switch
Hardware solutions / Routers & switches, VoIP, GSM, etc

Lenovo ThinkSystem DB400D FC Switch
Hardware solutions / Routers & switches, VoIP, GSM, etc

Lenovo - B6510 FC SAN Switch
Hardware solutions / Routers & switches, VoIP, GSM, etc

Lenovo - B6505 FC SAN Switch
Hardware solutions / Routers & switches, VoIP, GSM, etc

Lenovo - B300 FC SAN Switch
Hardware solutions / Routers & switches, VoIP, GSM, etc

Brocade - 6505 FC SAN Switch
Hardware solutions / Routers & switches, VoIP, GSM, etc

Vendor Lenovo

Security Bulletin

This security bulletin contains information about 2 vulnerabilities.

1) Information disclosure

EUVDB-ID: #VU61561

Risk: Medium

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-27796

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A remote user can read the contents of any file on the filesystem utilizing one of a few available binaries.

Mitigation

Install update from vendor's website.

Vulnerable software versions

Lenovo ThinkSystem DB800D FC Switch: All versions

Lenovo ThinkSystem DB720S FC Switch: All versions

Lenovo ThinkSystem DB630S FC Switch: All versions

Lenovo ThinkSystem DB620S FC Switch: All versions

Lenovo ThinkSystem DB610S FC Switch: All versions

Lenovo ThinkSystem DB400D FC Switch: All versions

Lenovo - B6510 FC SAN Switch: All versions

Lenovo - B6505 FC SAN Switch: All versions

Lenovo - B300 FC SAN Switch: All versions

Brocade - 6505 FC SAN Switch: All versions

External links

http://support.lenovo.com/lu/uk/product_security/LEN-79718


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Use of hard-coded credentials

EUVDB-ID: #VU61562

Risk: High

CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-27797

CWE-ID: CWE-798 - Use of Hard-coded Credentials

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain full access to vulnerable system.

The vulnerability exists due to presence of hard-coded credentials in application code. A remote unauthenticated attacker can access the affected system using the hard-coded credentials.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

Lenovo ThinkSystem DB800D FC Switch: All versions

Lenovo ThinkSystem DB720S FC Switch: All versions

Lenovo ThinkSystem DB630S FC Switch: All versions

Lenovo ThinkSystem DB620S FC Switch: All versions

Lenovo ThinkSystem DB610S FC Switch: All versions

Lenovo ThinkSystem DB400D FC Switch: All versions

Lenovo - B6510 FC SAN Switch: All versions

Lenovo - B6505 FC SAN Switch: All versions

Lenovo - B300 FC SAN Switch: All versions

Brocade - 6505 FC SAN Switch: All versions

External links

http://support.lenovo.com/lu/uk/product_security/LEN-79718


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###