First published: Wed Nov 03 2021(Updated: )
Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, have a buffer overflow vulnerability in the remote GetDumpFile command that could allow a user to attempt various attacks. In non-secure mode, the user is unauthenticated
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Emulex HBA Manager | <11.4.425.0 | |
Broadcom One Command Manager | <12.8.542.31 | |
<11.4.425.0 | ||
<12.8.542.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42772 has been classified as a high-severity vulnerability due to its potential for remote exploitation.
To fix CVE-2021-42772, upgrade to Broadcom Emulex HBA Manager version 11.4.425.0 or higher and One Command Manager version 12.8.542.31 or higher.
CVE-2021-42772 affects versions of Broadcom Emulex HBA Manager before 11.4.425.0 and One Command Manager before 12.8.542.31.
CVE-2021-42772 is a buffer overflow vulnerability that can be exploited if the software is not configured in Strictly Local Management mode.
Yes, CVE-2021-42772 can be exploited remotely if the application is running in a non-secure mode.