First published: Fri Nov 12 2021(Updated: )
Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, have a buffer overflow vulnerability in the remote firmware download feature that could allow remote unauthenticated users to perform various attacks. In non-secure mode, the user is unauthenticated.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Emulex HBA Manager | >=11.0.0<11.4.425.0 | |
Broadcom Emulex HBA Manager | >=12.0.0<12.8.542.31 | |
>=11.0.0<11.4.425.0 | ||
>=12.0.0<12.8.542.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42774 has a high severity due to its potential for remote exploitation leading to various attacks.
To fix CVE-2021-42774, upgrade your Broadcom Emulex HBA Manager or One Command Manager to versions 11.4.425.0 or 12.8.542.31 or later.
CVE-2021-42774 is caused by a buffer overflow vulnerability in the remote firmware download feature when not installed in Strictly Local Management mode.
Organizations using Broadcom Emulex HBA Manager or One Command Manager versions below 11.4.425.0 and 12.8.542.31 are affected by CVE-2021-42774.
Yes, CVE-2021-42774 can be exploited by remote unauthenticated users if the software is not configured in Strictly Local Management mode.