CVE-2021-27794
HIGHBrocade Fabric OS <v.9.0.1a,v8.2.3a,v7.4.2h - Auth Bypass
Title source: llmDescription
A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a and v7.4.2h could allow a user to Login with empty password, and invalid password through telnet, ssh and REST.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2021-1552
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210819-0001/
Scores
CVSS v3
7.8
EPSS
0.0006
EPSS Percentile
18.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-287
Status
published
Products (1)
broadcom/fabric_operating_system
< 7.4.2h
Published
Aug 12, 2021
Tracked Since
Feb 18, 2026