CVE-2021-42775 Information
Jun 07, 2022
cve
Description
Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31 if not installed in Strictly Local Management mode have a vulnerability in the remote firmware download feature that could allow a user to place or replace an arbitrary file on the remote host. In non-secure mode the user is unauthenticated.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Reference
https://www.broadcom.com/products/storage/fibre-channel-host-bus-adapters/emulex-hba-manager https://docs.broadcom.com/doc/elx_HBAManager-Lin-RN12811-101.pdf
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.1
Share on: