A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command.
This specific exploitation is only possible on IP Extension platforms: Brocade 7810, Brocade 7840, Brocade 7850 and on Brocade X6 or X7 directors with an SX-6 Extension blade installed. The attacker must be logged into the switch via SSH or serial console to conduct the attack.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Nov 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Brocade
Brocade fabric Os |
|
CPEs | cpe:2.3:o:brocade:fabric_os:-:*:*:*:*:*:*:* | |
Vendors & Products |
Brocade
Brocade fabric Os |
|
Metrics |
ssvc
|
Thu, 21 Nov 2024 06:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This specific exploitation is only possible on IP Extension platforms: Brocade 7810, Brocade 7840, Brocade 7850 and on Brocade X6 or X7 directors with an SX-6 Extension blade installed. The attacker must be logged into the switch via SSH or serial console to conduct the attack. | |
Title | Privileged escalation via crafted use of portcfg command | |
Weaknesses | CWE-77 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: brocade
Published: 2024-11-21T05:53:34.442Z
Updated: 2024-11-21T17:52:58.535Z
Reserved: 2024-08-05T22:49:54.345Z
Link: CVE-2024-7517
Vulnrichment
Updated: 2024-11-21T14:03:44.236Z
NVD
No data.
Redhat
No data.