Description
The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading memory addresses outside the intended range. An unauthenticated attacker could discover a request, which could bypass the authentication process.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-14532 | The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading memory addresses outside the intended range. An unauthenticated attacker could discover a request, which could bypass the authentication process. |
References
History
No history.
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2024-08-03T21:33:15.770Z
Reserved: 2021-02-26T00:00:00.000Z
Link: CVE-2021-27791
No data.
Status : Modified
Published: 2021-08-12T15:15:07.737
Modified: 2024-11-21T05:58:34.420
Link: CVE-2021-27791
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD