CVE-2022-33185
Summary
| CVE | CVE-2022-33185 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-25 21:15:00 UTC |
| Updated | 2023-02-28 18:01:00 UTC |
| Description | Several commands in Brocade Fabric OS before Brocade Fabric OS v.9.0.1e, and v9.1.0 use unsafe string functions to process user input. Authenticated local attackers could abuse these vulnerabilities to exploit stack-based buffer overflows, allowing arbitrary code execution as the root user account. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Broadcom | Fabric Operating System | All | All | All | All |
| Operating System | Broadcom | Fabric Operating System | 9.1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BSA-2022-2078 | MISC | www.broadcom.com | |
| CVE-2022-33185 Brocade Fabric OS Vulnerability | NetApp Product Security | CONFIRM | security.netapp.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.