BSA-2017-382

Brocade Fabric OS

2 more products

21514

13 October 2017

25 August 2017

Closed

Critical

9.4

N/A

CVE-2017-9765

Summary

Security Advisory ID : BSA-2017-382

Component : gSOAP

Revision : 2.0: Interim

Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via a large XML document, aka Devil's Ivy. NOTE: the large document would be blocked by many common web-server configurations on general-purpose computers.

Affected Products

Brocade is investigating its product lines to determine which products may be affected by this vulnerability and the impact on each affected product.

Products Confirmed Not Vulnerable

Brocade NetIron OS, Brocade Network OS, Brocade ServerIron ADX, and Brocade SLX-OS are confirmed not affected by this vulnerability.

Workaround

There are no workarounds that address this vulnerability.


Revision History

Version Change Date
1.0 Initial Publication August 25, 2017
2.0 Updated to address ADX October 13, 2017