Impact
The vulnerability arises when Brocade Fabric OS processes trunk configuration operations; it parses user‑supplied list strings into heap arrays without enforcing bounds on the number of elements. An authenticated administrator can send a REST API request with an excessive number of list delimiters, which triggers heap corruption that can either crash the service or allow the attacker to execute arbitrary code at the privilege level of the device.
Affected Systems
Systems running Brocade Fabric OS before version 10.0.1 are affected. All devices that process trunk configuration operations over the REST interface are at risk until they apply the 10.0.1 security update.
Risk and Exploitability
The CVSS score of 8.5 reflects high severity. EPSS is not available and the vulnerability is not currently listed in CISA KEV. Exploitation requires authenticated REST API access, but once authenticated an attacker can exploit the heap overflow to crash the service or gain code execution.
OpenCVE Enrichment