Impact
The vulnerability is a session context forgery in the Brocade Fabric OS web management daemon that accepts session structures from any local process without authentication‑checking. An attacker can forge administrative session data, enabling them to assume full web management privileges without legitimate credentials.
Affected Systems
Brocade Fabric OS version 9.2.2d and 10.0.0 through 10.0.0a1 are impacted. 9.2.2d is affected in the 9.2.x branch and any 10.0.x release prior to 10.0.1 is also vulnerable.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity risk. EPSS data is not available, but the exploit requires local process interaction with the daemon, making it a local privilege escalation vector. The vulnerability is not listed in the CISA KEV catalog, yet the potential to gain unrestricted administrative access warrants urgent attention.
OpenCVE Enrichment