Impact
The vulnerability is an input validation and output encoding flaw in the web management interface of Brocade Fabric OS versions prior to 10.0.1. When configuring Federated Authentication, the system does not sanitize the Identity Provider issuer parameter, allowing an attacker to inject arbitrary web server directives. This injection can prevent the web management daemon from starting, resulting in service denial, or can alter the web server’s security controls, potentially weakening protection mechanisms. The weakness is classified as CWE-93: Improper Constraint on Output.
Affected Systems
Brocade Fabric OS, all releases older than version 10.0.1.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated administrator or an attacker who can supply crafted Federated Authentication configuration files during an import routine. The attack vector is thus limited to privileged users with access to the configuration import feature. Given the moderate severity and the requirement for local or privileged access, the risk is considered moderate, but the potential for service disruption makes patching a priority.
OpenCVE Enrichment