Impact
Brocade Fabric OS exposes a REST API that, prior to version 10.0.1, accepts crafted input parameters that allow an authenticated user to inject system commands into the underlying shell. The result is arbitrary command execution with the privileges of the service account, leading to possible compromise of confidentiality, integrity, and availability. This weakness is classified as CWE‑78, command injection.
Affected Systems
All Brocade Fabric OS installations running a version earlier than 10.0.1 are affected. The vendor has released a security update in Fabric OS 10.0.1 that removes the vulnerability. Administrators should confirm their running version before planning remediation.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a valid authentication token to the REST API, meaning the attacker must either compromise a legitimate user account or have privileged network access to the management interface. The combination of authentication and the need to craft malicious parameters suggests the likelihood of successful exploitation is moderate, but the potential impact is severe.
OpenCVE Enrichment