Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vg73-mjx3-8p9g

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading memory addresses outside the intended range. An unauthenticated attacker could discover a request, which could bypass the authentication process.

The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading memory addresses outside the intended range. An unauthenticated attacker could discover a request, which could bypass the authentication process.

EPSS

Процентиль: 58%
0.00366
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 5.4
nvd
больше 4 лет назад

The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading memory addresses outside the intended range. An unauthenticated attacker could discover a request, which could bypass the authentication process.

EPSS

Процентиль: 58%
0.00366
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-287