BSA-2021-1491
21583
10 May 2021
10 May 2021
Closed
Medium
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N - 4.3
N/A
CVE-2021-27791
Summary
Security Advisory ID : BSA-2021-1491
Component : Web Application Service
Revision : 1.0
The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading memory addresses outside the intended range. An unauthenticated attacker could discover a request, which could bypass the authentication process.
Affected Products
Brocade Fabric OS versions before v9.0.1a and v8.2.3a
Products Confirmed Not Vulnerable
No other Brocade Fibre Channel Products from Broadcom products are currently known to be affected by this vulnerability.
Solution
A security update has been provided in Brocade Fabric OS versions v9.0.1a and v8.2.3a
Credit
This issue was discovered through security testing.
Revision History
Version | Change | Date |
---|---|---|
1.0 | Initial Publication | May 10, 2021 |