Database/Control plane, storage & DevOps
Brocade Fabric OS REST API: Multiple buffer overflows in the Fabric OS REST API reachable by an unauthenticated remote
Impact
Multiple buffer overflows in the Fabric OS REST API reachable by an unauthenticated remote attacker. The REST API is what modern SAN automation drives, so it is enabled in exactly the environments that also automate zoning — meaning the vulnerable interface is the one wired into your provisioning pipeline.
Who can reach it
Unauthenticated, remote to the FOS REST API on v8.2.1 through v8.2.1d, and 8.2.2 before v8.2.2c.
What to do
Fabric OS upgrade plus reboot, per fabric. If you do not use the REST API, disabling it is a live config change that removes the exposure without a maintenance window. Related: CVE-2020-15374, CVE-2020-15371.
References
Related entries
- Marvell QConvergeConsole GUI 5.5.0.64 - 5.5.0.74 (QLogic HBA management): The earlier cluster on the same consoleCVE-2020-15639 · Marvell QConvergeConsole GUI 5.5.0.64 - 5.5.0.74 (QLogic HBA management)Critical
- Slurm (Gentoo ebuild pkg_postinst): The Gentoo packaging runs chown across paths on the live root filesystem duringCVE-2020-36770 · Slurm (Gentoo ebuild pkg_postinst)Critical
- Cisco Nexus 3000/9000 (internal file management service): Unauthenticated remote file write, read and delete as rootCVE-2021-1361 · Cisco Nexus 3000/9000 (internal file management service)Critical
- GitLab: unauthenticated SSRF through webhooks reaches the internal networkCVE-2021-22175 · GitLab (webhook request handling)Critical
- Brocade Fabric OS (hard-coded credentials): Documented hard-coded credentials in Brocade Fabric OSCVE-2021-27797 · Brocade Fabric OS (hard-coded credentials)Critical
- etcd: Authentication flaw via the debug functionCVE-2021-28235 · etcdCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.