CVE-2021-42774: Buffer Overflow
Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, have a buffer overflow vulnerability in the remote firmware download feature that could allow remote unauthenticated users to perform various attacks. In non-secure mode, the user is unauthenticated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42774?
CVE-2021-42774 has a high severity due to its potential for remote exploitation leading to various attacks.
How do I fix CVE-2021-42774?
To fix CVE-2021-42774, upgrade your Broadcom Emulex HBA Manager or One Command Manager to versions 11.4.425.0 or 12.8.542.31 or later.
What causes CVE-2021-42774?
CVE-2021-42774 is caused by a buffer overflow vulnerability in the remote firmware download feature when not installed in Strictly Local Management mode.
Who is affected by CVE-2021-42774?
Organizations using Broadcom Emulex HBA Manager or One Command Manager versions below 11.4.425.0 and 12.8.542.31 are affected by CVE-2021-42774.
Can CVE-2021-42774 be exploited remotely?
Yes, CVE-2021-42774 can be exploited by remote unauthenticated users if the software is not configured in Strictly Local Management mode.