Impact
SupportLink diagnostic collection utilities in Brocade Fabric OS store the full URL of any authenticated HTTP proxy used. The stored proxy URL includes cleartext credentials. When a diagnostic support bundle is generated, these credentials are embedded within the bundle.
Affected Systems
Brocade Fabric OS versions earlier than 10.0.1 are affected. The vulnerability applies to all deployments using SupportLink with proxy authentication configured. Users or support personnel who can retrieve or read support bundles have the potential to uncover the proxy credentials.
Risk and Exploitability
The CVSS score of 6.8 indicates a Medium risk. The EPSS score is not available, suggesting limited publicly known exploitation activity. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is any party that can access the diagnostic bundle, whether through shared file‑system permissions or third‑party support access. An attacker who obtains the cleartext credentials could leverage them to authenticate to the HTTP proxy, possibly facilitating further lateral movement or unauthorized web traffic.
OpenCVE Enrichment