VendorsBroadcomfabric_operating_systemany version
Vulnerabilities

Broadcom Fabric Operating System (FOS) any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

84CVEs
CVE-2021-22890
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server and then wrongly "short-cut" the host handshake. When confusing the tickets, a HTTPS proxy can trick libcurl to use the wrong session ticket resume for the host and thereby circumvent the server TLS certificate check and make a MITM attack to be possible to perform unnoticed. Note that such a malicious HTTPS proxy needs to provide a certificate that curl will accept for the MITMed server for an attack to work - unless curl has been told to ignore the server certificate check.
Published 2021-04-01 · Modified
4.3EPSS 0.031
CVE-2020-15376
Brocade Fabric OS versions before v9.0.0 and after version v8.1.0, configured in Virtual Fabric mode contain a weakness in the ldap implementation that could allow a remote ldap user to login in the Brocade Fibre Channel SAN switch with "user" privileges if it is not associated with any groups.
Published 2020-12-11 · Modified
4.3EPSS 0.009
CVE-2024-29953
Encoded session passwords on session storage for Virtual Fabric platforms
Published 2024-06-25 · Analyzed
4.3EPSS 0.003
CVE-2023-5973
Truncated port name
Published 2024-04-05 · Modified
4.3EPSS 0.002
← Prev3 / 3