Database/Firmware, BMC & network fabric
Brocade Fabric OS (config and secnotify processes): Running a routine security scan against the SAN switch crashes
Impact
Running a routine security scan against the SAN switch crashes the config and secnotify processes. Worth carrying because it inverts the usual advice: the compliance activity you are required to perform is itself the outage. Operators who scan their storage fabric on a schedule have been taking unexplained SAN switch faults from their own tooling.
Who can reach it
Any security scanner reaching the switch's management services — no attacker required.
What to do
Fabric OS upgrade to v9.0.0 / v8.2.2d / v8.2.1e or later, firmware install plus reboot. Until then, exclude FOS management addresses from automated vulnerability scans or scan them only in a maintenance window.
References
Related entries
- GRUB2 (rmmod command): Use-after-free in the rmmod commandCVE-2020-25632 · GRUB2 (rmmod command)High
- GRUB2 (grub_parser_split_cmdline): Stack buffer overflow from variable expansion in the GRUB command lineCVE-2020-27749 · GRUB2 (grub_parser_split_cmdline)High
- AMD SEV / SEV-ES - Owner's Certificate Authority (OCA) certificate parsing: Insufficient validation when parsing OCACVE-2021-26406 · AMD SEV / SEV-ES - Owner's Certificate Authority (OCA) certificate parsingHigh
- Arista EOS (VXLAN match rule in IPv4 ACL): If an IPv4 access list contains a VXLAN match rule, that rule and every ruleCVE-2021-28505 · Arista EOS (VXLAN match rule in IPv4 ACL)High
- Arista EOS (TerminAttr / IPsec): TerminAttr leaks IPsec sensitive material in plaintext to authorized usersCVE-2021-28508 · Arista EOS (TerminAttr / IPsec)High
- GRUB2 (PNG reader): A crafted PNG in the boot splash path causes an out-of-bounds write in GRUBCVE-2021-3695 · GRUB2 (PNG reader)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.