First published: Wed Feb 05 2020(Updated: )
Brocade Fabric OS Versions before v8.2.2a and v8.2.1d could expose the credentials of the remote ESRS server when these credentials are given as a command line option when configuring the ESRS client.
Credit: sirt@brocade.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Fabric Operating System | >=8.2.1<8.2.1d | |
Broadcom Fabric Operating System | >=8.2.2<8.2.2a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16203 is a vulnerability in Brocade Fabric OS versions before v8.2.2a and v8.2.1d that could expose the credentials of the remote ESRS server when configuring the ESRS client.
This vulnerability can be exploited by providing the credentials of the remote ESRS server as a command line option during the configuration of the ESRS client.
The affected software versions are Brocade Fabric OS versions before v8.2.2a and v8.2.1d.
CVE-2019-16203 has a severity rating of high with a CVSS score of 7.5.
To fix CVE-2019-16203, upgrade to Brocade Fabric OS version v8.2.2a or v8.2.1d or later.