First published: Thu Feb 08 2018(Updated: )
Cross-site scripting (XSS) vulnerability in the web-based management interface of Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) versions before 7.4.2b, 8.1.2 and 8.2.0 could allow remote attackers to execute arbitrary code or access sensitive browser-based information.
Credit: sirt@brocade.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Fabric Operating System | <7.4.2b | |
Broadcom Fabric Operating System | =8.0.2 | |
Broadcom Fabric Operating System | =8.1.1 | |
Brocade Fabric OS | =8.0.1b1 | |
Brocade Fabric OS | =8.0.2b1 | |
Brocade Fabric OS | =8.1.0c1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2017-6225.
The severity of CVE-2017-6225 is medium with a CVSS score of 6.1.
The affected software for CVE-2017-6225 includes Brocade Fabric Operating System versions before 7.4.2b, 8.0.2, and 8.1.1, and Brocade Fabric OS versions 8.0.1b1, 8.0.2b1, and 8.1.0c1.
CVE-2017-6225 could allow remote attackers to execute arbitrary code or access sensitive browser-based information.
Yes, you can mitigate the vulnerability by updating to Brocade Fabric OS versions 7.4.2b, 8.1.2, or 8.2.0.