BSA-2021-1480
21693
10 May 2021
10 May 2021
Closed
High
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L - 8.8
N/A
CVE-2020-15377
Summary Security Advisory ID : BSA-2021-1480 Component : Webtools Revision : 1.0
Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-Side Request Forgery (SSRF).
Attackers can utilize SSRF to cause the target service to carry out requests to servers or services which otherwise would be inaccessible.
Affected Products
Brocade SANnav versions before SANnav 2.1.1
Products Confirmed Not Vulnerable
No other Brocade Fibre Channel Products from Broadcom products are currently known to be affected by this vulnerability.
Solution
A security update has been provided in Brocade SANnav 2.1.1 and higher releases.
Workaround
Credit
This issue was discovered through security testing.
Revision History
Version | Change | Date |
---|---|---|
1.0 | Initial Publication | May 10, 2021 |