CVE-2021-27790

The command ipfilter in Brocade Fabric OS before Brocade Fabric OS v.9.0.1a, v8.2.3, and v8.2.0_CBN4, and v7.4.2h uses unsafe string function to process user input. Authenticated attackers can abuse this vulnerability to exploit stack-based buffer overflows, allowing execution of arbitrary code as the root user account.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
brocadeCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
VendorProductVersion
broadcomfabric_operating_system
𝑥
< 7.4.2h
broadcomfabric_operating_system
8.0.0 ≤
𝑥
< 8.2.0_cbn4
broadcomfabric_operating_system
8.2.1 ≤
𝑥
< 8.2.3
broadcomfabric_operating_system
9.0.0 ≤
𝑥
< 9.0.1a
𝑥
= Vulnerable software versions