BSA-2021-1491

Brocade Fabric OS

2 more products

21583

10 May 2021

10 May 2021

Closed

Medium

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N - 4.3

N/A

CVE-2021-27791

Summary

Security Advisory ID : BSA-2021-1491

Component : Web Application Service

Revision : 1.0

The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading memory addresses outside the intended range. An unauthenticated attacker could discover a request, which could bypass the authentication process.

Affected Products

Brocade Fabric OS versions before v9.0.1a and v8.2.3a

Products Confirmed Not Vulnerable

No other Brocade Fibre Channel Products from Broadcom products are currently known to be affected by this vulnerability.

Solution

A security update has been provided in Brocade Fabric OS versions v9.0.1a and v8.2.3a

Credit

This issue was discovered through security testing.

Revision History

Version Change Date
1.0 Initial Publication May 10, 2021