BSA-2021-1480

Brocade Fabric OS

2 more products

21693

10 May 2021

10 May 2021

Closed

High

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L - 8.8

N/A

CVE-2020-15377

Summary

Security Advisory ID : BSA-2021-1480

Component : Webtools

Revision : 1.0

Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-Side Request Forgery (SSRF). 
Attackers can utilize SSRF to cause the target service to carry out requests to servers or services which otherwise would be inaccessible.

Affected Products

Brocade SANnav versions before SANnav 2.1.1

Products Confirmed Not Vulnerable

No other Brocade Fibre Channel Products from Broadcom products are currently known to be affected by this vulnerability.

Solution

A security update has been provided in Brocade SANnav 2.1.1 and higher releases. 

Workaround

Credit

This issue was discovered through security testing.

Revision History

Version Change Date
1.0 Initial Publication May 10, 2021