A path transversal vulnerability in
Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to
gain access to files outside the intended directory potentially leading
to the disclosure of sensitive information.


Note: Admin level privilege is required on the switch in order to exploit
Advisories
Source ID Title
EUVD EUVD EUVD-2025-28065 A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain access to files outside the intended directory potentially leading to the disclosure of sensitive information. Note: Admin level privilege is required on the switch in order to exploit
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 20 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Jun 2025 02:30:00 +0000

Type Values Removed Values Added
Description A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain access to files outside the intended directory potentially leading to the disclosure of sensitive information. Note: Admin level privilege is required on the switch in order to exploit
Title Path transversal vulnerability potentially leading to sensitive information disclosure
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2025-06-20T15:21:20.092Z

Reserved: 2025-05-13T18:33:06.354Z

Link: CVE-2025-4661

cve-icon Vulnrichment

Updated: 2025-06-20T15:21:12.710Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-19T03:15:25.530

Modified: 2025-06-23T20:16:59.783

Link: CVE-2025-4661

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-06-20T13:24:21Z