CVE Vulnerabilities

CVE-2021-27792

Published: Aug 12, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The request handling functions in web management interface of Brocade Fabric OS versions before v9.0.1a, v8.2.3a, and v7.4.2h do not properly handle malformed user input, resulting in a service crash. An authenticated attacker could use this weakness to cause the FOS HTTP application handler to crash, requiring a reboot.

Affected Software

NameVendorStart VersionEnd Version
Fabric_operating_systemBroadcom*7.4.2h (excluding)
Fabric_operating_systemBroadcom8.0.0 (including)8.2.3a (excluding)
Fabric_operating_systemBroadcom9.0.0 (including)9.0.1a (excluding)

References