Critical severity9.1NVD Advisory· Published Nov 12, 2021· Updated Jun 17, 2026
CVE-2021-42775
CVE-2021-42775
Description
Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, have a vulnerability in the remote firmware download feature that could allow a user to place or replace an arbitrary file on the remote host. In non-secure mode, the user is unauthenticated.
Affected products
4cpe:2.3:a:broadcom:emulex_hba_manager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:broadcom:emulex_hba_manager:*:*:*:*:*:*:*:*range: >=11.0.0,<11.4.425.0
- (no CPE)range: <11.4.425.0
- Broadcom/Emulex HBA Manager/One Command Managerdescription
- Range: <12.8.542.31
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.