First published: Thu Aug 12 2021(Updated: )
The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading memory addresses outside the intended range. An unauthenticated attacker could discover a request, which could bypass the authentication process.
Credit: sirt@brocade.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Fabric Operating System | >=8.2.1<8.2.3a | |
Broadcom Fabric Operating System | >=9.0.0<9.0.1a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27791 is a vulnerability in Brocade Fabric OS Web application service that allows a client to send a malformed authentication header, resulting in reading memory addresses outside the intended range.
Brocade Fabric OS versions 8.2.1 to 8.2.3a and 9.0.0 to 9.0.1a are affected by CVE-2021-27791.
CVE-2021-27791 has a severity score of 5.4, classified as medium.
To fix CVE-2021-27791, users should upgrade Brocade Fabric OS to a version that is not affected by the vulnerability.
You can find more information about CVE-2021-27791 in the following advisories: [NetApp Advisory](https://security.netapp.com/advisory/ntap-20210819-0002/) and [Brocade Security Advisory](https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2021-1491).