Junglewise Threat Intelligence

CVE-2016-8201: Brocade Virtual Traffic Manager CSRF in management interface

CVE-2016-8201 · Severity: high · CVSS 8 · Published 2017-01-14

Vendors: Brocade.

Executive brief

Brocade Virtual Traffic Manager is a software-based load balancer used to manage and optimize network traffic for applications. A security flaw could allow an attacker to trick an authenticated administrator into unknowingly performing management actions on the traffic manager cluster. This could lead to unauthorized configuration changes, potentially disrupting service or compromising the security of the managed network traffic.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability (CWE-352) exists in the management interface of Brocade Virtual Traffic Manager. The vulnerability allows a remote attacker to bypass intended security restrictions by tricking a logged-in user into executing malicious requests. Successful exploitation requires the victim to have an active administrative session and to interact with a malicious link or website. An attacker can leverage this to make unauthorized administrative changes to the traffic manager cluster, impacting the integrity and availability of the system. The issue is addressed in versions released after 11.0.

Affected products

  • Brocade Virtual Traffic Manager versions prior to and including 11.0

Timeline

  • 2017-01-14: disclosed: NVD Published Date

References