CVE-2020-15388
- EPSS 0.23%
- Veröffentlicht 18.03.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:05:27
A vulnerability in the Brocade Fabric OS before Brocade Fabric OS v9.0.1a, v8.2.3, v8.2.0_CBN4, and v7.4.2h could allow an authenticated CLI user to abuse the history command to write arbitrary content to files.
CVE-2021-27797
- EPSS 0.3%
- Veröffentlicht 21.02.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:58:35
Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain access to the system.
CVE-2021-27796
- EPSS 0.31%
- Veröffentlicht 21.02.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:58:35
A vulnerability in Brocade Fabric OS versions before Brocade Fabric OS v8.0.1b, v7.4.1d could allow an authenticated attacker within the restricted shell environment (rbash) as either the “user” or “factory” account, to read the contents of any file ...
CVE-2021-27794
- EPSS 0.06%
- Veröffentlicht 12.08.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:58:34
A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a and v7.4.2h could allow a user to Login with empty password, and invalid password through telnet, ssh and REST.
CVE-2021-27793
- EPSS 0.32%
- Veröffentlicht 12.08.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:58:34
ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fabric OS before Brocade Fabric OS v8.2.3a and after v8.2.0 could cause a user with a valid account to ...
CVE-2021-27792
- EPSS 0.05%
- Veröffentlicht 12.08.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:58:34
The request handling functions in web management interface of Brocade Fabric OS versions before v9.0.1a, v8.2.3a, and v7.4.2h do not properly handle malformed user input, resulting in a service crash. An authenticated attacker could use this weakness...
CVE-2021-27791
- EPSS 0.37%
- Veröffentlicht 12.08.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:58:34
The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading m...
CVE-2021-27790
- EPSS 0.05%
- Veröffentlicht 12.08.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:58:34
The command ipfilter in Brocade Fabric OS before Brocade Fabric OS v.9.0.1a, v8.2.3, and v8.2.0_CBN4, and v7.4.2h uses unsafe string function to process user input. Authenticated attackers can abuse this vulnerability to exploit stack-based buffer ov...
CVE-2020-15387
- EPSS 0.12%
- Veröffentlicht 09.06.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 05:05:27
The host SSH servers of Brocade Fabric OS before Brocade Fabric OS v7.4.2h, v8.2.1c, v8.2.2, v9.0.0, and Brocade SANnav before v2.1.1 utilize keys of less than 2048 bits, which may be vulnerable to man-in-the-middle attacks and/or insecure SSH commun...
CVE-2020-15386
- EPSS 0.38%
- Veröffentlicht 09.06.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 05:05:27
Brocade Fabric OS prior to v9.0.1a and 8.2.3a and after v9.0.0 and 8.2.2d may observe high CPU load during security scanning, which could lead to a slower response to CLI commands and other operations.