Impact
An out-of-bounds memory read flaw is present in the web management daemon of Brocade Fabric OS versions before 10.0.1. Unauthenticated HTTP requests can supply extreme numerical values in query parameters, bypassing array index checks. This causes an invalid memory dereference that crashes the web management process, resulting in a denial of service and temporary disruption of the management plane.
Affected Systems
The vulnerability affects Brocade Fabric OS. Any version older than 10.0.1 is vulnerable. The affected product is the web management daemon component of Fabric OS.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity risk. EPSS data is not available, so the exact exploitation probability is uncertain, but the vulnerability is unauthenticated and exploitable remotely via HTTP, meaning attackers could trigger a crash without any credentials. The vulnerability is not listed in CISA’s KEV catalog, but because it can disrupt management‑plane availability, a system that relies on continuous management should consider patching immediately.
OpenCVE Enrichment