Impact
A stack-based buffer overflow exists in the Internet Key Exchange (IKEv2) protocol handler of Brocade Fabric OS versions prior to 10.0.1. The overflow is triggered when processing an oversized Nonce payload in an initial IKEv2 key exchange request, which is sent over UDP port 500. An unauthenticated remote attacker can send a single crafted packet to an extension switch or blade running IPsec-enabled Fibre Channel over IP circuits, causing the data‑plane process to crash and resulting in a denial of service. The vulnerability does not directly disclose sensitive data or enable privilege escalation, but it completely disrupts the data‑plane operation of the device.
Affected Systems
All Brocade Fabric OS devices running versions earlier than 10.0.1 are affected, including extension switches and blades that handle IPsec-enabled FCIP circuits.
Risk and Exploitability
The CVSS score is 6.0, indicating a moderate impact. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring an unauthenticated UDP packet sent to port 500. While the exploit condition only requires the presence of an IKEv2‑enabled FCIP circuit, any successful exploitation leads to a crash of the data‑plane process. No publicly available exploit code is documented at this time, but the simple nature of the attack vector and the lack of authentication suggest that it could be used in a distributed denial‑of‑service scenario if the attacker gains network visibility to the target devices.
OpenCVE Enrichment