BSA-2022-1844
21293
04 May 2022
04 May 2022
Closed
High
8.0 - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
N/A
CVE-2022-28165
Summary Security Advisory ID : BSA-2022-1844 Component : RBAC Revision : 1.0
A vulnerability in the role-based access control (RBAC) functionality of the Brocade SANNav before 2.2.0 could allow an authenticated, remote attacker to access resources that they should not be able to access and perform actions that they should not be able to perform. The vulnerability exists because restrictions are not performed on Server side to ensure the user has required permission before processing requests.
Affected Products.Brocade SANnav - Fixed in Brocade SANnav 2.2.0
Product Confirmed Not VulnerableNo other Brocade Fibre Channel Products from Broadcom products are currently known to be affected by this vulnerability.
Credit
The issue was discovered in penetration testing.
Revision History
Version |
Change |
Date |
---|---|---|
1.0 |
Initial Publication |
May 3, 2022 |