CVE-2020-15375: Input Validation
Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0CBN3, v7.4.2g contain an improper input validation weakness in the command line interface when secccrypptocfg is invoked. The vulnerability could allow a local authenticated user to run arbitrary commands and perform escalation of privileges.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-15375.
What is the severity of CVE-2020-15375?
The severity of CVE-2020-15375 is medium with a severity value of 6.7.
Which software versions are affected by CVE-2020-15375?
Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g are affected by CVE-2020-15375.
What is the vulnerability description of CVE-2020-15375?
CVE-2020-15375 is an improper input validation weakness in the command line interface of Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g, which could allow a local authenticated user to run arbitrary commands and perform escalation of privileges.
How can I fix CVE-2020-15375?
To fix CVE-2020-15375, it is recommended to update Brocade Fabric OS to versions v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g or later.