Broadcom Fabric Operating System vulnerabilities

79 known vulnerabilities affecting broadcom/fabric_operating_system.

Total CVEs
79
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH37MEDIUM35

Vulnerabilities

Page 3 of 4
CVE-2021-27789MEDIUMCVSS 6.5fixed in 8.2.3a≥ 9.0.0, < 9.0.1a2022-03-18
CVE-2021-27789 [MEDIUM] CVE-2021-27789: The Web application of Brocade Fabric OS before versions Brocade Fabric OS v9.0.1a and v8.2.3a conta The Web application of Brocade Fabric OS before versions Brocade Fabric OS v9.0.1a and v8.2.3a contains debug statements that expose sensitive information to the program's standard output device. An attacker who has compromised the FOS system may utilize this weakness to capture sensitive information, such as user credentials.
nvd
CVE-2021-27797CRITICALCVSS 9.8≥ 7.0.0, ≤ 7.4.2h≥ 8.0.0, ≤ 8.0.2f+2 more2022-02-21
CVE-2021-27797 [CRITICAL] CWE-798 CVE-2021-27797: Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain access to the system.
nvd
CVE-2021-27796MEDIUMCVSS 6.5fixed in 7.4.1d≥ 8.0.0, < 8.0.1b2022-02-21
CVE-2021-27796 [MEDIUM] CVE-2021-27796: A vulnerability in Brocade Fabric OS versions before Brocade Fabric OS v8.0.1b, v7.4.1d could allow A vulnerability in Brocade Fabric OS versions before Brocade Fabric OS v8.0.1b, v7.4.1d could allow an authenticated attacker within the restricted shell environment (rbash) as either the “user” or “factory” account, to read the contents of any file on the filesystem utilizing one of a few available binaries.
nvd
CVE-2021-27794HIGHCVSS 7.8fixed in 7.4.2h≥ 8.0.0, < 8.2.3a+1 more2021-08-12
CVE-2021-27794 [HIGH] CWE-287 CVE-2021-27794: A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a and v7.4.2h could allow a user to Login with empty password, and invalid password through telnet, ssh and REST.
nvd
CVE-2021-27790HIGHCVSS 7.8fixed in 7.4.2h≥ 8.0.0, < 8.2.0_cbn4+2 more2021-08-12
CVE-2021-27790 [HIGH] CWE-787 CVE-2021-27790: The command ipfilter in Brocade Fabric OS before Brocade Fabric OS v.9.0.1a, v8.2.3, and v8.2.0_CBN4 The command ipfilter in Brocade Fabric OS before Brocade Fabric OS v.9.0.1a, v8.2.3, and v8.2.0_CBN4, and v7.4.2h uses unsafe string function to process user input. Authenticated attackers can abuse this vulnerability to exploit stack-based buffer overflows, allowing execution of arbitrary code as the root user account.
nvd
CVE-2021-27792HIGHCVSS 7.8fixed in 7.4.2h≥ 8.0.0, < 8.2.3a+1 more2021-08-12
CVE-2021-27792 [HIGH] CVE-2021-27792: The request handling functions in web management interface of Brocade Fabric OS versions before v9.0 The request handling functions in web management interface of Brocade Fabric OS versions before v9.0.1a, v8.2.3a, and v7.4.2h do not properly handle malformed user input, resulting in a service crash. An authenticated attacker could use this weakness to cause the FOS HTTP application handler to crash, requiring a reboot.
nvd
CVE-2021-27791MEDIUMCVSS 5.4≥ 8.2.1, < 8.2.3a≥ 9.0.0, < 9.0.1a2021-08-12
CVE-2021-27791 [MEDIUM] CWE-125 CVE-2021-27791: The function that is used to parse the Authentication header in Brocade Fabric OS Web application se The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading memory addresses outside the intended range. An unauthenticated attacker could discover a request, whi
nvd
CVE-2021-27793MEDIUMCVSS 5.3≥ 8.2.0, < 8.2.3≥ 9.0.0, < 9.0.1+3 more2021-08-12
CVE-2021-27793 [MEDIUM] CWE-863 CVE-2021-27793: ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabr ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fabric OS before Brocade Fabric OS v8.2.3a and after v8.2.0 could cause a user with a valid account to be unable to log into the switch.
nvd
CVE-2020-15383HIGHCVSS 7.5fixed in 8.2.1v8.2.1+7 more2021-06-09
CVE-2020-15383 [HIGH] CVE-2020-15383: Running security scans against the SAN switch can cause config and secnotify processes within the fi Running security scans against the SAN switch can cause config and secnotify processes within the firmware before Brocade Fabric OS v9.0.0, v8.2.2d and v8.2.1e to consume all memory leading to denial of service impacts possibly including a switch panic.
nvd
CVE-2020-15387HIGHCVSS 7.4fixed in 7.4.2≥ 8.2.0, < 8.2.1+10 more2021-06-09
CVE-2020-15387 [HIGH] CWE-326 CVE-2020-15387: The host SSH servers of Brocade Fabric OS before Brocade Fabric OS v7.4.2h, v8.2.1c, v8.2.2, v9.0.0, The host SSH servers of Brocade Fabric OS before Brocade Fabric OS v7.4.2h, v8.2.1c, v8.2.2, v9.0.0, and Brocade SANnav before v2.1.1 utilize keys of less than 2048 bits, which may be vulnerable to man-in-the-middle attacks and/or insecure SSH communications.
nvd
CVE-2020-15386MEDIUMCVSS 5.3v8.2.3v9.0.0a+2 more2021-06-09
CVE-2020-15386 [MEDIUM] CVE-2020-15386: Brocade Fabric OS prior to v9.0.1a and 8.2.3a and after v9.0.0 and 8.2.2d may observe high CPU load Brocade Fabric OS prior to v9.0.1a and 8.2.3a and after v9.0.0 and 8.2.2d may observe high CPU load during security scanning, which could lead to a slower response to CLI commands and other operations.
nvd
CVE-2020-15376MEDIUMCVSS 4.3≥ 8.1.0, < 9.0.02020-12-11
CVE-2020-15376 [MEDIUM] CVE-2020-15376: Brocade Fabric OS versions before v9.0.0 and after version v8.1.0, configured in Virtual Fabric mode Brocade Fabric OS versions before v9.0.0 and after version v8.1.0, configured in Virtual Fabric mode contain a weakness in the ldap implementation that could allow a remote ldap user to login in the Brocade Fibre Channel SAN switch with "user" privileges if it is not associated with any groups.
nvd
CVE-2020-15375MEDIUMCVSS 6.7fixed in 7.4.2g≥ 8.0.0, < 8.1.2k+3 more2020-12-11
CVE-2020-15375 [MEDIUM] CWE-20 CVE-2020-15375: Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g contain an Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g contain an improper input validation weakness in the command line interface when secccrypptocfg is invoked. The vulnerability could allow a local authenticated user to run arbitrary commands and perform escalation of privileges.
nvd
CVE-2020-15374CRITICALCVSS 9.8v8.2.1v8.2.1a+8 more2020-09-25
CVE-2020-15374 [CRITICAL] CVE-2020-15374: Rest API in Brocade Fabric OS v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c is vulnerabl Rest API in Brocade Fabric OS v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c is vulnerable to multiple instances of reflected input.
nvd
CVE-2020-15373CRITICALCVSS 9.8v8.2.1v8.2.1a+8 more2020-09-25
CVE-2020-15373 [CRITICAL] CWE-119 CVE-2020-15373: Multiple buffer overflow vulnerabilities in REST API in Brocade Fabric OS versions v8.2.1 through v8 Multiple buffer overflow vulnerabilities in REST API in Brocade Fabric OS versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c could allow remote unauthenticated attackers to perform various attacks.
nvd
CVE-2020-15371CRITICALCVSS 9.8v8.0.0v8.0.1+33 more2020-09-25
CVE-2020-15371 [CRITICAL] CWE-94 CVE-2020-15371: Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, contains code injection and privilege escalation vulnerability.
nvd
CVE-2020-15369HIGHCVSS 8.8v8.2.1v8.2.1a+7 more2020-09-25
CVE-2020-15369 [HIGH] CWE-521 CVE-2020-15369: Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2 Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c does not obfuscate the password field, which could expose users’ credentials of the remote server. An authenticated user could obtain the exposed password credentials to gain access to the remote host.
nvd
CVE-2018-6448HIGHCVSS 7.5fixed in 9.0.02020-09-25
CVE-2018-6448 [HIGH] CVE-2018-6448: A vulnerability in the management interface in Brocade Fabric OS Versions before Brocade Fabric OS v A vulnerability in the management interface in Brocade Fabric OS Versions before Brocade Fabric OS v9.0.0 could allow a remote attacker to perform a denial of service attack on the vulnerable host.
nvd
CVE-2018-6449MEDIUMCVSS 6.1fixed in 9.0.02020-09-25
CVE-2018-6449 [MEDIUM] CWE-79 CVE-2018-6449: Host Header Injection vulnerability in the http management interface in Brocade Fabric OS versions b Host Header Injection vulnerability in the http management interface in Brocade Fabric OS versions before v9.0.0 could allow a remote attacker to exploit this vulnerability by injecting arbitrary HTTP headers
nvd
CVE-2020-15372MEDIUMCVSS 5.5fixed in 7.4.2g≥ 8.0.0, < 8.1.2k+4 more2020-09-25
CVE-2020-15372 [MEDIUM] CWE-913 CVE-2020-15372: A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2.2a1 A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2.2a1, 8.2.2c, v7.4.2g, v8.2.0_CBN3, v8.2.1e, v8.1.2k, v9.0.0, could allow a local authenticated attacker to modify shell variables, which may lead to an escalation of privileges or bypassing the logging.
nvd