Impact
A local privilege escalation flaw resides in the system logging daemon of Brocade Fabric OS. The daemon accepts logging configuration changes over internal I/O channels that lack proper access controls, letting any local user write a malformed configuration. Because the daemon does not sanitize input before generating its configuration file, an attacker can inject arbitrary directives. When the logging service reloads, those directives are executed with system privileges, allowing the attacker to gain full root rights on the affected device.
Affected Systems
The flaw affects Brocade Fabric OS versions earlier than 9.2.2d and from 10.0.0 through 10.0.0a1. Users running these releases or earlier are at risk, while versions 9.2.2d and later, and 10.0.1, contain the fix.
Risk and Exploitability
The vulnerability has a CVSS score of 8.5, indicating high severity. The EPSS score is not available, but the flaw requires only local access—any user with local login can exploit it. The flaw is not yet listed in CISA’s KEV catalog, suggesting no widespread exploitation reports yet. Nevertheless, the combination of high severity, local‑user exploitation, and absence of protection mechanisms creates a significant risk for any system that hosts Brocade Fabric OS and allows local users to interact with the system logging interface.
OpenCVE Enrichment