Impact
An improper file permission and lack of authorization protection in the diagnostic kernel module subsystem of Brocade Fabric OS allows an unprivileged local user to trigger privileged hardware tests, force system error conditions, reset hardware blades, or disrupt storage fabric operations. This flaw can lead to unauthorized control over hardware components and cause service interruptions, affecting the confidentiality of system operations, the integrity of device state, and the availability of the storage fabric.
Affected Systems
Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1 are affected. Versions 9.2.2d and 10.0.1 provide a security update that mitigates this vulnerability.
Risk and Exploitability
The CVSS score of 7 indicates a high severity. The EPSS score is not available, making the exploitation likelihood uncertain; however, the flaw is reachable by any local user with no additional privileges. Because the vulnerability is listed in the vendor’s security advisory but not yet in the CISA KEV catalog, it has not yet been confirmed as exploited in the wild. The likely attack vector is local; an attacker would need physical or local network access to the Fabric OS host.
OpenCVE Enrichment