Brocade Fibre Channel SAN Switch Vulnerability in LDAP Implementation
CVE-2020-15376

4.3MEDIUM

Key Information:

Vendor
Broadcom
Vendor
CVE Published:
11 December 2020

Summary

A flaw exists in Brocade Fabric OS configurations utilizing Virtual Fabric mode, which enables remote LDAP users to gain 'user' privileges when not assigned to any groups. This vulnerability could lead to unauthorized access and elevate risks within Fibre Channel SAN environments.

Affected Version(s)

Brocade Fabric OS Brocade Fabric OS versions before v9.0.0 and after version v8.1.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.