Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-27791

Опубликовано: 12 авг. 2021
Источник: nvd
CVSS3: 5.4
CVSS2: 5.5
EPSS Низкий

Описание

The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading memory addresses outside the intended range. An unauthenticated attacker could discover a request, which could bypass the authentication process.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:*
Версия от 8.2.1 (включая) до 8.2.3a (исключая)
cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:*
Версия от 9.0.0 (включая) до 9.0.1a (исключая)

EPSS

Процентиль: 58%
0.00366
Низкий

5.4 Medium

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 5.4
github
больше 3 лет назад

The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading memory addresses outside the intended range. An unauthenticated attacker could discover a request, which could bypass the authentication process.

EPSS

Процентиль: 58%
0.00366
Низкий

5.4 Medium

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-125