BSA-2021-1486

Brocade Fabric OS

2 more products

21692

10 May 2021

10 May 2021

Closed

High

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N - 8.1

N/A

CVE-2020-15385

Summary

Security Advisory ID : BSA-2021-1486

Component : File Listing

Revision : 1.0

Brocade SANnav before version 2.1.1 allows an authenticated attacker to list directories, and list files without permission. As a result, users without permission can see folders, and hidden files, and can create directories without permission.

Affected Products

Brocade SANnav versions before SANnav 2.1.1

Products Confirmed Not Vulnerable

No other Brocade Fibre Channel Products from Broadcom products are currently known to be affected by this vulnerability.

Solution

A security update has been provided in Brocade SANnav 2.1.1 and higher releases. 

Workaround

Credit

This issue was discovered through security testing.

Revision History

Version Change Date
1.0 Initial Publication May 10, 2021