CVE-2021-27791
12.08.2021, 15:15
The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading memory addresses outside the intended range. An unauthenticated attacker could discover a request, which could bypass the authentication process.Enginsight
Vendor | Product | Version |
---|---|---|
broadcom | fabric_operating_system | 8.2.1 ≤ 𝑥 < 8.2.3a |
broadcom | fabric_operating_system | 9.0.0 ≤ 𝑥 < 9.0.1a |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References