Broadcom

Fabric Operating System

95 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 12.08.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 05:58:34

The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading m...

  • EPSS 0.05%
  • Veröffentlicht 12.08.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 05:58:34

The command ipfilter in Brocade Fabric OS before Brocade Fabric OS v.9.0.1a, v8.2.3, and v8.2.0_CBN4, and v7.4.2h uses unsafe string function to process user input. Authenticated attackers can abuse this vulnerability to exploit stack-based buffer ov...

  • EPSS 0.12%
  • Veröffentlicht 09.06.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 05:05:27

The host SSH servers of Brocade Fabric OS before Brocade Fabric OS v7.4.2h, v8.2.1c, v8.2.2, v9.0.0, and Brocade SANnav before v2.1.1 utilize keys of less than 2048 bits, which may be vulnerable to man-in-the-middle attacks and/or insecure SSH commun...

  • EPSS 0.38%
  • Veröffentlicht 09.06.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 05:05:27

Brocade Fabric OS prior to v9.0.1a and 8.2.3a and after v9.0.0 and 8.2.2d may observe high CPU load during security scanning, which could lead to a slower response to CLI commands and other operations.

  • EPSS 0.47%
  • Veröffentlicht 09.06.2021 15:15:08
  • Zuletzt bearbeitet 21.11.2024 05:05:27

Running security scans against the SAN switch can cause config and secnotify processes within the firmware before Brocade Fabric OS v9.0.0, v8.2.2d and v8.2.1e to consume all memory leading to denial of service impacts possibly including a switch pan...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 01.04.2021 18:15:12
  • Zuletzt bearbeitet 09.06.2025 15:15:23

curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 01.04.2021 18:15:12
  • Zuletzt bearbeitet 09.06.2025 15:15:24

curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving fro...

  • EPSS 0.81%
  • Veröffentlicht 04.01.2021 18:15:13
  • Zuletzt bearbeitet 09.06.2025 16:15:30

The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.

  • EPSS 0.23%
  • Veröffentlicht 11.12.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:05:26

Brocade Fabric OS versions before v9.0.0 and after version v8.1.0, configured in Virtual Fabric mode contain a weakness in the ldap implementation that could allow a remote ldap user to login in the Brocade Fibre Channel SAN switch with "user" privil...

  • EPSS 0.05%
  • Veröffentlicht 11.12.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:05:26

Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g contain an improper input validation weakness in the command line interface when secccrypptocfg is invoked. The vulnerability could allow a local authenticated ...