Impact
An unauthenticated remote command injection flaw exists in the Brocade SANnav orchestrator HTTP service. The vulnerability allows an attacker with network‑adjacent access to inject arbitrary administrative switch CLI commands and container management instructions, potentially altering Fibre Channel fabric switch configurations or manipulating application container runtimes. The weakness aligns with CWE‑77, which represents command injection.
Affected Systems
This issue impacts all Brocade SANnav deployments running versions earlier than 3.0.1a. The affected product is the Brocade SANnav orchestrator. No specific sub‑model or firmware level is listed beyond the general product name and version threshold.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. Although the EPSS score is not available, the absence of a KEV listing suggests limited current exploitation but does not preclude future attacks. Attackers must first reach the orchestrator service, which is typically exposed within the same local area network or managed tenant network. Once the HTTP interface is accessed, the injection can be performed without prior authentication, yielding full administrative privileges over switches and containers.
OpenCVE Enrichment