First published: Wed Dec 06 2023(Updated: )
Brocade Fabric OS (FOS) hardware platforms running any version of Brocade Fabric OS software, which supports the license string format; contain cryptographic issues that could allow for the installation of forged or fraudulent license keys. This would allow attackers or a malicious party to forge a counterfeit license key that the Brocade Fabric OS platform would authenticate and activate as if it were a legitimate license key.
Credit: sirt@brocade.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Broadcom Fabric Operating System | ||
Any of | ||
Broadcom Brocade 300 | ||
Broadcom Brocade 610 | ||
Broadcom Brocade 6505 | ||
Broadcom Brocade 6510 | ||
Broadcom Brocade 6520 | ||
Broadcom Brocade 7800 | ||
Broadcom Brocade 7810 | ||
Broadcom Brocade 7840 | ||
Broadcom Brocade G620 | ||
Broadcom Brocade G630 | ||
Broadcom Brocade X6-4 Director | ||
Broadcom Brocade X6-8 Director |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27795 has been assessed to have a high severity due to its potential for exploitation by attackers to forge license keys.
To fix CVE-2021-27795, please ensure that you update your Brocade Fabric OS software to the latest version provided by Broadcom.
The risks associated with CVE-2021-27795 include the installation of unauthorized licenses, leading to unauthorized access to systems and services.
Devices running any version of Brocade Fabric OS that support the license string format are affected by CVE-2021-27795.
Currently, there is no documented workaround for CVE-2021-27795 other than applying the necessary software updates.