CVE-2021-42773: High severity broadcom emulex hba manager vulnerability
Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, could allow a user to retrieve an arbitrary file from a remote host with the GetDumpFile command. In non-secure mode, the user is unauthenticated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42773?
CVE-2021-42773 is considered a high-severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2021-42773?
To fix CVE-2021-42773, update to Broadcom Emulex HBA Manager version 11.4.425.0 or 12.8.542.31 or later.
What are the affected versions in CVE-2021-42773?
CVE-2021-42773 affects Broadcom Emulex HBA Manager versions prior to 11.4.425.0 and 12.8.542.31.
What does CVE-2021-42773 allow an attacker to do?
CVE-2021-42773 allows an attacker to retrieve arbitrary files from a remote host if the software is not in Strictly Local Management mode.
Is authentication required to exploit CVE-2021-42773?
No, exploitation of CVE-2021-42773 can occur without authentication in non-secure mode.