Impact
The vulnerability is an authorization logic flaw in the Fabric OS REST API gateway that allows an authenticated user to spoof HTTP headers used for access control. Because the gateway solely trusts client‑supplied headers, any user with a valid REST session can forge values and bypass restrictions. This permits low‑privilege users to call internal management endpoints that expose chassis metadata, memory patrolling status, and firmware integrity audit logs, resulting in the disclosure of sensitive operational information.
Affected Systems
Brocade Fabric OS versions prior to 10.0.1 are impacted. The flaw originates in the internal REST API gateway handling of authentication headers, and the security update available in Fabric OS 10.0.1 removes the vulnerable check.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. EPSS data is not available and the issue is not listed in the CISA KEV catalog. An attacker requires a valid REST session to craft spoofed headers, so the attack can only be executed once credentialed access is obtained; no public exploits are known, but the simple logic bypass makes the vulnerability straightforward to test internally.
OpenCVE Enrichment