The command ipfilter in Brocade Fabric OS before Brocade Fabric OS v.9.0.1a, v8.2.3, and v8.2.0_CBN4, and v7.4.2h uses unsafe string function to process user input. Authenticated attackers can abuse this vulnerability to exploit stack-based buffer overflows, allowing execution of arbitrary code as the root user account.
2021-08-12T15:15:07.697
2024-11-21T05:58:34.290
Modified
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | broadcom | fabric_operating_system | < 7.4.2h | Yes |
Operating System | broadcom | fabric_operating_system | < 8.2.0_cbn4 | Yes |
Operating System | broadcom | fabric_operating_system | < 8.2.3 | Yes |
Operating System | broadcom | fabric_operating_system | < 9.0.1a | Yes |