Impact
The vulnerability is an authentication bypass and command injection flaw in the inter-switch remote execution service of Brocade Fabric OS. An attacker that can send specially crafted IPC frames to a switch in the fabric can cause the switch to process commands at an elevated level without verifying parameters. This allows the attacker to elevate privileges to root and execute arbitrary commands locally or on other fabric members where remote execution is enabled.
Affected Systems
The flaw affects Brocade Fabric OS versions prior to 9.2.2d and 10.0.0 through 10.0.0a1. The security update is provided for Fabric OS 9.2.2d and 10.0.1.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high risk. The exploit requires that the attacker already be connected to the fabric via a switch, so the threat surface is limited to an attacker with local network access to a fabric device. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Given the possibility of executing root commands, systems in a production fabric should patch immediately or implement mitigations.
OpenCVE Enrichment