Impact
An OS command injection flaw in the time and zone management subsystem of Brocade Fabric OS allows an authenticated low‑privilege administrator to submit a crafted timezone string containing shell metacharacters. The system fails to sanitize these inputs before they are passed to shell execution routines, enabling the attacker to escape the restricted management environment and execute arbitrary shell commands with elevated privileges. This results in complete compromise of the device, compromising confidentiality, integrity, and availability.
Affected Systems
The flaw affects Brocade Fabric OS versions prior to 9.2.2d and 10.0.0 through 10.0.0a1. Upgrades to Fabric OS 9.2.2d or 10.0.1 contain the fix.
Risk and Exploitability
The CVSS score of 8.6 classifies this as high severity, and the vulnerability is not listed in the CISA KEV catalog. EPSS data is unavailable, so the probability of exploitation is unknown; however, the necessary conditions—an authenticated low‑privilege administrative user and access to REST API or configuration download endpoints—are likely to be met in many environments. Attackers could thus leverage this flaw from within the management plane to gain full system control.
OpenCVE Enrichment