A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This specific exploitation is only possible on IP Extension platforms: Brocade 7810, Brocade 7840, Brocade 7850 and on Brocade X6 or X7 directors with an SX-6 Extension blade installed. The attacker must be logged into the switch via SSH or serial console to conduct the attack.
History

Thu, 21 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Brocade
Brocade fabric Os
CPEs cpe:2.3:o:brocade:fabric_os:-:*:*:*:*:*:*:*
Vendors & Products Brocade
Brocade fabric Os
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 21 Nov 2024 06:00:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This specific exploitation is only possible on IP Extension platforms: Brocade 7810, Brocade 7840, Brocade 7850 and on Brocade X6 or X7 directors with an SX-6 Extension blade installed. The attacker must be logged into the switch via SSH or serial console to conduct the attack.
Title Privileged escalation via crafted use of portcfg command
Weaknesses CWE-77
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published: 2024-11-21T05:53:34.442Z

Updated: 2024-11-21T17:52:58.535Z

Reserved: 2024-08-05T22:49:54.345Z

Link: CVE-2024-7517

cve-icon Vulnrichment

Updated: 2024-11-21T14:03:44.236Z

cve-icon NVD

No data.

cve-icon Redhat

No data.