CVE-2021-27793Incorrect Authorization in Fabric Operating System

Severity
5.3MEDIUMNVD
EPSS
0.3%
top 44.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12
Latest updateMay 24

Description

ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fabric OS before Brocade Fabric OS v8.2.3a and after v8.2.0 could cause a user with a valid account to be unable to log into the switch.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5brocade/brocade_fabric_osVersions before Brocade Fabric OS v9.0.1b and after 9.0.0, also before Brocade Fabric OS v8.2.3a and after v8.2.0
NVDbroadcom/fabric_operating_system8.2.08.2.3+4

🔴Vulnerability Details

2
GHSA
GHSA-j9pj-ff73-q8xm: ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v92022-05-24
CVEList
CVE-2021-27793: ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v92021-08-12
CVE-2021-27793 — Incorrect Authorization | cvebase