{ "schema_version": "1.4.0", "id": "GHSA-mr9f-f2w7-mmmf", "modified": "2022-05-24T19:20:36Z", "published": "2022-05-24T19:20:36Z", "aliases": [ "CVE-2021-42774" ], "details": "Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, have a buffer overflow vulnerability in the remote firmware download feature that could allow remote unauthenticated users to perform various attacks. In non-secure mode, the user is unauthenticated.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42774" }, { "type": "WEB", "url": "https://docs.broadcom.com/doc/elx_HBAManager-Lin-RN12811-101.pdf" }, { "type": "WEB", "url": "https://www.broadcom.com/products/storage/fibre-channel-host-bus-adapters/emulex-hba-manager" } ], "database_specific": { "cwe_ids": [ "CWE-120" ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2021-11-12T02:15:00Z" } }