CVE-2017-3752: IBM 1:10g Firmware

High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.

An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaws may result in attackers being able to erase or alter the routing tables of one or many routers, switches, or other devices that support OSPF within a routing domain.

Affected products

  • IBM 1:10g Firmware: up to and including 7.4.16.0
  • IBM 1g l2-7 Slb: up to and including 21.0.24.0
  • IBM EN2092 1gb Firmware: up to and including 7.8.16.0
  • IBM Fabric CN4093 10gb Firmware: up to and including 7.8.16.0
  • IBM Fabric EN4093/EN4093R 10gb Firmware: up to and including 7.8.16.0
  • IBM g8052 Firmware: up to and including 7.9.19.0
  • IBM g8124 Firmware: up to and including 7.11.9.0
  • IBM g8124e Firmware: up to and including 7.11.9.0
  • IBM g8264 Firmware: up to and including 7.9.19.0
  • IBM g8264cs Firmware: up to and including 7.8.16.0
  • IBM g8264t Firmware: up to and including 7.9.19.0
  • IBM g8316 Firmware: up to and including 7.9.19.0
  • IBM g8332 Firmware: up to and including 7.7.25.0
  • IBM Layer 2/3 Copper Firmware: up to and including 5.3.10.0
  • IBM Virtual Fabric 10gb: up to and including 7.8.12.0
  • Lenovo Fabric CN4093 10gb Firmware: up to and including 8.4.3.0
  • Lenovo Fabric EN4093R 10gb Firmware: up to and including 8.4.3.0
  • Lenovo g8052 Firmware: up to and including 8.4.3.0
  • Lenovo g8124e Firmware: up to and including 8.4.3.0
  • Lenovo g8264 Firmware: up to and including 8.4.3.0
  • Lenovo g8264cs Firmware: up to and including 8.4.3.0
  • Lenovo g8272 Firmware: up to and including 8.4.3.0
  • Lenovo g8296 Firmware: up to and including 8.4.3.0
  • Lenovo g8332 Firmware: up to and including 8.4.3.0
  • Lenovo SI4091 Firmware: up to and including 8.4.3.0

Published 2017-08-09. Last modified 2026-06-17.