Description
An information disclosure vulnerability exists in the SupportLink diagnostic collection utilities of Brocade Fabric OS versions before 10.0.1. When SupportLink is configured to use an authenticated HTTP proxy, the system stores the full proxy URL. Anyone with access to the diagnostic support bundle, such as support personnel or users with access to file shares where support bundles are stored, can extract these cleartext proxy credentials.
Published: 2026-10-08
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

SupportLink diagnostic collection utilities in Brocade Fabric OS store the full URL of any authenticated HTTP proxy used. The stored proxy URL includes cleartext credentials. When a diagnostic support bundle is generated, these credentials are embedded within the bundle.

Affected Systems

Brocade Fabric OS versions earlier than 10.0.1 are affected. The vulnerability applies to all deployments using SupportLink with proxy authentication configured. Users or support personnel who can retrieve or read support bundles have the potential to uncover the proxy credentials.

Risk and Exploitability

The CVSS score of 6.8 indicates a Medium risk. The EPSS score is not available, suggesting limited publicly known exploitation activity. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is any party that can access the diagnostic bundle, whether through shared file‑system permissions or third‑party support access. An attacker who obtains the cleartext credentials could leverage them to authenticate to the HTTP proxy, possibly facilitating further lateral movement or unauthorized web traffic.

Generated by OpenCVE AI on October 8, 2026 at 04:25 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 10.0.1


OpenCVE Recommended Actions

  • Apply the Brocade Fabric OS 10.0.1 security update or later version to eliminate the information disclosure flaw.
  • Restrict or remove permissions on locations where diagnostic support bundles are stored, limiting access to only the essential personnel.
  • If updating immediately is not possible, disable proxy authentication in SupportLink or ensure that any proxy credentials are removed from bundles before distribution.

Generated by OpenCVE AI on October 8, 2026 at 04:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Brocade
Brocade fabric Os
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 03:00:00 +0000

Type Values Removed Values Added
Description An information disclosure vulnerability exists in the SupportLink diagnostic collection utilities of Brocade Fabric OS versions before 10.0.1. When SupportLink is configured to use an authenticated HTTP proxy, the system stores the full proxy URL. Anyone with access to the diagnostic support bundle, such as support personnel or users with access to file shares where support bundles are stored, can extract these cleartext proxy credentials.
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Brocade Fabric Os
cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T02:55:58.519Z

Reserved: 2026-09-08T22:51:12.166Z

Link: CVE-2026-87672

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T03:16:36.810

Modified: 2026-10-08T03:16:36.810

Link: CVE-2026-87672

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T04:30:13Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File