ZeroHour

CVE-2021-27791

CVSS 3.1
5.4 medium
EPSS
<1%p47
Published
()
Modified
Description

The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading memory addresses outside the intended range. An unauthenticated attacker could discover a request, which could bypass the authentication process.

Vendors
broadcom
Products
fabric operating system
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.