Description
An out-of-bounds memory read vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1. Unauthenticated HTTP endpoints process specific URL query parameters without validating array index boundaries or performing numerical range checks. An unauthenticated remote attacker can exploit this issue by sending a single, crafted HTTP request containing extreme numerical values in the query string. This causes an invalid memory dereference, resulting in a crash of the web management process (Denial of Service) and potential temporary management-plane disruption.
Published: 2026-10-08
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

An out-of-bounds memory read flaw is present in the web management daemon of Brocade Fabric OS versions before 10.0.1. Unauthenticated HTTP requests can supply extreme numerical values in query parameters, bypassing array index checks. This causes an invalid memory dereference that crashes the web management process, resulting in a denial of service and temporary disruption of the management plane.

Affected Systems

The vulnerability affects Brocade Fabric OS. Any version older than 10.0.1 is vulnerable. The affected product is the web management daemon component of Fabric OS.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity risk. EPSS data is not available, so the exact exploitation probability is uncertain, but the vulnerability is unauthenticated and exploitable remotely via HTTP, meaning attackers could trigger a crash without any credentials. The vulnerability is not listed in CISA’s KEV catalog, but because it can disrupt management‑plane availability, a system that relies on continuous management should consider patching immediately.

Generated by OpenCVE AI on October 8, 2026 at 03:23 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 10.0.1


OpenCVE Recommended Actions

  • Apply the Brocade Fabric OS 10.0.1 firmware update or later to fix the out-of-bounds read in the web management daemon
  • Limit external network access to the web management endpoints with firewall or network segmentation to block unauthenticated HTTP requests
  • Monitor web‑management logs for abnormal crashes or repeated invalid requests to detect potential exploitation attempts

Generated by OpenCVE AI on October 8, 2026 at 03:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Brocade Fabric OS Web Management Daemon
First Time appeared Brocade
Brocade fabric Os
Weaknesses CWE-190
CWE-787
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 02:45:00 +0000

Type Values Removed Values Added
Description An out-of-bounds memory read vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1. Unauthenticated HTTP endpoints process specific URL query parameters without validating array index boundaries or performing numerical range checks. An unauthenticated remote attacker can exploit this issue by sending a single, crafted HTTP request containing extreme numerical values in the query string. This causes an invalid memory dereference, resulting in a crash of the web management process (Denial of Service) and potential temporary management-plane disruption.
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Brocade Fabric Os
cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T02:22:02.036Z

Reserved: 2026-09-08T22:51:12.166Z

Link: CVE-2026-87671

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T03:16:36.650

Modified: 2026-10-08T03:16:36.650

Link: CVE-2026-87671

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T03:30:16Z

Weaknesses