Black Lantern Security (BLSOPS)

Share this post

Privileged Directory Traversal in Brocade Fabric OS

blog.blacklanternsecurity.com
Vulnerability Research

Privileged Directory Traversal in Brocade Fabric OS

Brocade: CVE-2021-27798: Fabric OS (Multiple Versions)

Cody Martin
Aug 1, 2022
1
Share this post

Privileged Directory Traversal in Brocade Fabric OS

blog.blacklanternsecurity.com

Brocade Fabric operating system (OS) is used for monitoring physical, protocol, and application layer data points of a storage area network (SAN) in real time. Black Lantern Security (BLS) identified a vulnerability that allows any authenticated user to bypass restricted shell (rbash) limitations and list the entire file structure of the affected device. This includes all binaries available to the user. When this vulnerability is combined with the two previously disclosed vulnerabilities (CVE-2021-27796, CVE-2021-27797) affecting the same software versions, an attacker can authenticate using weak default credentials, list all files, and read all files on the system.

CVE-2021-27798 - Authenticated Privileged Directory Traversal

Brocade Fabric OS <8.0.1b and <7.4.1d was discovered to have an authenticated privileged directory traversal vulnerability. Utilizing CVE-2021-27797, an authenticated attacker has the ability to list all directory contents on the system. This can be achieved with the more binary and tab-completion.

Privileged Directory Traversal

Remediation

Brocade SIRT was notified of this vulnerability and has since issued the following solution:

Brocade recommends Customers run supported Brocade software versions.

Timeline

2021-09-22: Contacted Brocade SIRT to Report Vulnerabilities
2021-09-24: Initial Response from Brocade SIRT
2021-11-01: Brocade SIRT Provided Analysis
2022-07-28: Brocade SIRT Provided Details for Disclosure
2022-07-28: Public Disclosure

Share

Share this post

Privileged Directory Traversal in Brocade Fabric OS

blog.blacklanternsecurity.com
Comments
TopNewCommunity

No posts

Ready for more?

© 2023 Black Lantern Security (BLSOPS)
Privacy ∙ Terms ∙ Collection notice
Start WritingGet the app
Substack is the home for great writing