Brocade Fibre Channel SAN Switch Vulnerability in LDAP Implementation
CVE-2020-15376
4.3MEDIUM
Summary
A flaw exists in Brocade Fabric OS configurations utilizing Virtual Fabric mode, which enables remote LDAP users to gain 'user' privileges when not assigned to any groups. This vulnerability could lead to unauthorized access and elevate risks within Fibre Channel SAN environments.
Affected Version(s)
Brocade Fabric OS Brocade Fabric OS versions before v9.0.0 and after version v8.1.0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved