Description
The request handling functions in web management interface of Brocade Fabric OS versions before v9.0.1a, v8.2.3a, and v7.4.2h do not properly handle malformed user input, resulting in a service crash. An authenticated attacker could use this weakness to cause the FOS HTTP application handler to crash, requiring a reboot.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_misc
https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2021-1490
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210819-0002/
Vendor Advisory x_refsource_misc
https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2021-1492
Scores
CVSS v3
7.8
EPSS
0.0005
EPSS Percentile
15.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (1)
broadcom/fabric_operating_system
< 7.4.2h
Published
Aug 12, 2021
Tracked Since
Feb 18, 2026