CVE-2017-3765: Lenovo Enterprise Network Operating System
High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.
In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console, Telnet, SSH, and Web interfaces. This bypass mechanism can be accessed when performing local authentication under specific circumstances. If exploited, admin-level access to the switch is granted.
Affected products
- Lenovo Enterprise Network Operating System: before 8.4.6.0 (fixed in 8.4.6.0)
Published 2018-01-10. Last modified 2026-06-17.