CVE-2022-3786 and CVE-2022-3602: X.509 Email Address Buffer Overflows

Brocade Fabric OS

2 more products

21224

01 November 2022

01 November 2022

Closed

High

N/A

N/A

CVE-2022-3786 and CVE-2022-3602

Summary

Security Advisory ID : BSA-2022-2115

Component : OpenSSL

Revision : 1.0

On November 1st, 2022 the OpenSSL Project disclosed CVE-2022-3602 and CVE-2022-3786 present in OpenSSL 3.0.x... The vulnerabilities were initially rated as critical severity vulnerabilities but are now disclosed as high.

More at: https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/

The Brocade Security Team has been working with Brocade engineering teams to determine the impact on Brocade Fibre Channel Products from Broadcom.

Products Confirmed Not Affected

  • Brocade Fabric OS
  • Brocade Active Support Connectivity Gateway (ASC-G)
  • Brocade SANnav

Revision History

Version

Change

Date

1.0

Initial Publication

Nov 1, 2022