Database/Control plane, storage & DevOps
Brocade Fabric OS REST API: Multiple buffer overflows in the Fabric OS REST API reachable by an unauthenticated remote
Impact
Multiple buffer overflows in the Fabric OS REST API reachable by an unauthenticated remote attacker. The REST API is what modern SAN automation drives, so it is enabled in exactly the environments that also automate zoning — meaning the vulnerable interface is the one wired into your provisioning pipeline.
Who can reach it
Unauthenticated, remote to the FOS REST API on v8.2.1 through v8.2.1d, and 8.2.2 before v8.2.2c.
What to do
Fabric OS upgrade plus reboot, per fabric. If you do not use the REST API, disabling it is a live config change that removes the exposure without a maintenance window. Related: CVE-2020-15374, CVE-2020-15371.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.