This specific exploitation is only possible on IP Extension platforms: Brocade 7810, Brocade 7840, Brocade 7850 and on Brocade X6 or X7 directors with an SX-6 Extension blade installed. The attacker must be logged into the switch via SSH or serial console to conduct the attack.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48860 | A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This specific exploitation is only possible on IP Extension platforms: Brocade 7810, Brocade 7840, Brocade 7850 and on Brocade X6 or X7 directors with an SX-6 Extension blade installed. The attacker must be logged into the switch via SSH or serial console to conduct the attack. |
Fri, 20 Feb 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Broadcom
Broadcom fabric Operating System |
|
| CPEs | cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Brocade fabric Operating System
|
Broadcom
Broadcom fabric Operating System |
Fri, 30 Jan 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brocade fabric Operating System
|
|
| CPEs | cpe:2.3:o:brocade:fabric_operating_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Brocade fabric Operating System
|
|
| Metrics |
cvssV3_1
|
Tue, 09 Sep 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 |
Tue, 09 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-78 |
Thu, 21 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brocade
Brocade fabric Os |
|
| CPEs | cpe:2.3:o:brocade:fabric_os:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Brocade
Brocade fabric Os |
|
| Metrics |
ssvc
|
Thu, 21 Nov 2024 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This specific exploitation is only possible on IP Extension platforms: Brocade 7810, Brocade 7840, Brocade 7850 and on Brocade X6 or X7 directors with an SX-6 Extension blade installed. The attacker must be logged into the switch via SSH or serial console to conduct the attack. | |
| Title | Privileged escalation via crafted use of portcfg command | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2025-09-09T19:02:20.886Z
Reserved: 2024-08-05T22:49:54.345Z
Link: CVE-2024-7517
Updated: 2024-11-21T14:03:44.236Z
Status : Analyzed
Published: 2024-11-21T11:15:35.990
Modified: 2026-02-20T21:22:06.937
Link: CVE-2024-7517
No data.
OpenCVE Enrichment
No data.
EUVD