Critical severity9.8NVD Advisory· Published Nov 12, 2021· Updated Jun 17, 2026
CVE-2021-42774
CVE-2021-42774
Description
Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, have a buffer overflow vulnerability in the remote firmware download feature that could allow remote unauthenticated users to perform various attacks. In non-secure mode, the user is unauthenticated.
Affected products
4cpe:2.3:a:broadcom:emulex_hba_manager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:broadcom:emulex_hba_manager:*:*:*:*:*:*:*:*range: >=11.0.0,<11.4.425.0
- (no CPE)range: <11.4.425.0, <12.8.542.31
- Broadcom/Emulex HBA Manager/One Command Managerdescription
- Range: <11.4.425.0, <12.8.542.31
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.