MEDIUM · 6.4

CVE-2021-27795

Brocade Fabric OS (FOS) hardware platforms running any version of Brocade Fabric OS software, which supports the license string format; contain cryptographic issues that could allow for the install...

Vulnerability Description

Brocade Fabric OS (FOS) hardware platforms running any version of Brocade Fabric OS software, which supports the license string format; contain cryptographic issues that could allow for the installation of forged or fraudulent license keys. This would allow attackers or a malicious party to forge a counterfeit license key that the Brocade Fabric OS platform would authenticate and activate as if it were a legitimate license key.

CVSS Score

6.4

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
HIGH

Affected Products

VendorProductVersions
BroadcomFabric Operating SystemAll versions
BroadcomBrocade 300-
BroadcomBrocade 610-
BroadcomBrocade 6505-
BroadcomBrocade 6510-
BroadcomBrocade 6520-
BroadcomBrocade 7800-
BroadcomBrocade 7810-
BroadcomBrocade 7840-
BroadcomBrocade G620-
BroadcomBrocade G630-
BroadcomBrocade X6-4 Director-
BroadcomBrocade X6-8 Director-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-27795?

CVE-2021-27795 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Brocade Fabric OS (FOS) hardware platforms running any version of Brocade Fabric OS software, which supports the license string format; contain cryptographic issues that could allow for the install...

How severe is CVE-2021-27795?

CVE-2021-27795 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-27795?

Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Fabric Operating System, Broadcom Brocade 300, Broadcom Brocade 610, Broadcom Brocade 6505, Broadcom Brocade 6510.