Vulnerability CVE-2021-27796


Published: 2022-02-21

Description:
A vulnerability in Brocade Fabric OS versions before Brocade Fabric OS v8.0.1b, v7.4.1d could allow an authenticated attacker within the restricted shell environment (rbash) as either the ??user? or ??factory? account, to read the contents of any file on the filesystem utilizing one of a few available binaries.

Type:

NVD-CWE-noinfo

CVSS2 => (AV:N/AC:L/Au:S/C:C/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Complete
None
None
Affected software
Broadcom -> Fabric operating system 

 References:
https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2021-1721

Copyright 2024, cxsecurity.com

 

Back to Top