BSA-2022-1844

Brocade Fabric OS

2 more products

21293

04 May 2022

04 May 2022

Closed

High

8.0 - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

N/A

CVE-2022-28165

Summary

Security Advisory ID : BSA-2022-1844

Component : RBAC

Revision : 1.0

A vulnerability in the role-based access control (RBAC) functionality of the Brocade SANNav before 2.2.0 could allow an authenticated, remote attacker to access resources that they should not be able to access and perform actions that they should not be able to perform. The vulnerability exists because restrictions are not performed on Server side to ensure the user has required permission before processing requests.

Affected Products.

Brocade SANnav - Fixed in Brocade SANnav 2.2.0

Product Confirmed Not Vulnerable

No other Brocade Fibre Channel Products from Broadcom products are currently known to be affected by this vulnerability.

Credit
The issue was discovered in penetration testing.

Revision History

Version

Change

Date

1.0

Initial Publication

May 3, 2022