Use of hard-coded credentials in Brocade Fabric OS - CVE-2021-27797

 

Use of hard-coded credentials in Brocade Fabric OS - CVE-2021-27797

Published: March 23, 2022


Vulnerability identifier: #VU61562
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-27797
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain full access to vulnerable system.

The vulnerability exists due to presence of hard-coded credentials in application code. A remote unauthenticated attacker can access the affected system using the hard-coded credentials.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Brocade Fabric OS
Brocade - 6505 FC SAN Switch
Lenovo - B300 FC SAN Switch
Lenovo - B6505 FC SAN Switch
Lenovo - B6510 FC SAN Switch
Lenovo ThinkSystem DB400D FC Switch
Lenovo ThinkSystem DB610S FC Switch
Lenovo ThinkSystem DB620S FC Switch
Lenovo ThinkSystem DB630S FC Switch
Lenovo ThinkSystem DB720S FC Switch
Lenovo ThinkSystem DB800D FC Switch
Connectrix (Brocade)

How to mitigate CVE-2021-27797

Install updates from vendor's website.

Brocade Fabric OS - addressed in versions 8.1.2h, 8.2.1c, 9.0.0
Connectrix (Brocade) - addressed in versions 7.4.2, 8.1.2h, 8.2.1c, 9.0.0

External References

Related Security Bulletins