Impact
Insecure access controls on internal service ports in older Brocade SANnav versions enable local, non‑administrative hosts to talk directly to backend management services. A local attacker can exploit this bypass to send management commands to connected Fabric OS switches using the SANnav management account. This flaw permits an attacker to alter switch configuration, potentially disrupt networking services, and gain privileged control over fabric components.
Affected Systems
The vulnerability affects Brocade SANnav devices running any version earlier than 3.0.1a. Users running these legacy firmware releases are at risk, regardless of external network exposure.
Risk and Exploitability
The CVSS score of 8.7 indicates a high‑severity flaw, and while the EPSS score is not available, the absence of a KEV listing suggests the vulnerability has not yet been widely exploited. The attack requires local presence on a host with user rights that are not administrative, but the compromised host can issue commands that run with the SANnav management user’s privileges on Fabric OS switches. The CWE-284 classification highlights that inadequate access control is the root cause, meaning the exploit remains effective as long as the affected firmware is in use.
OpenCVE Enrichment