Impact
A stack‑based buffer overflow exists in the diagnostic execution utility of Brocade Fabric OS. When diagnostic command arguments are processed, the utility tokenizes user input into an internal array without checking bounds, leading to a memory overwrite. The overflow causes a process crash, resulting in a denial of service. The weakness is identified as CWE‑121.
Affected Systems
Brocade Fabric OS versions earlier than 10.0.1 are affected. Administrators with suitable credentials can trigger the vulnerability by issuing a diagnostic command that contains more arguments than the utility can safely handle.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high severity. Although no exploit probability score is publicly available and the issue is not listed in the CISA KEV catalog, the requirement of authenticated administrative access means only privileged operators can trigger it. Successful exploitation requires crafting a diagnostic command with an excessive number of tokens, which the vulnerable utility will process, causing a crash and service interruption.
OpenCVE Enrichment