Lenovo engineers have discovered a backdoor (CVE-2017-3765) in the firmware of its RackSwitch and BladeCenter. The Chinese company said it found the backdoor after an internal security audit it conducted on products added to its list after acquisitions of other companies.
Lenovo says the backdoor only affects RackSwitch and BladeCenter switches running ENOS (Enterprise Network Operating System). The backdoor was added to ENOS in 2004 when Nortel's Blade Server Switch Business Unit (BSSBU) took over maintenance, and it appears to have remained in the firmware even after Lenovo acquired IBM.
The so-called “HP Backdoor” is not a hidden account, but an authentication bypass mechanism that occurs under very strict conditions. RackSwitch and BladeCenter support various authentication methods, including SSH, Telnet, web interface, and serial console. An attacker can exploit this backdoor by bypassing authentication when these switches have various authentication mechanisms and security features disabled or even enabled. “The existence of mechanisms that bypass authentication or authorization is unacceptable to Lenovo and does not follow its product security or practices. Lenovo has removed this mechanism from the ENOS source code and has issued updated firmware for the affected products,” the company said.
The updates are available for newer Lenovo-branded switches, as well as older IBM switches that are still in production and running ENOS.

