Impact
An Access Control Bypass exists in the Role‑Based Access Control validation engine of Brocade Fabric OS versions prior to 10.0.1. Because the engine misclassifies certain non‑standard action opcodes during permission checks, the system incorrectly grants permission to execute restricted administrative operations. The vulnerability is a classic example of CWE‑269, allowing authenticated users who only have read‑only management privileges to elevate their capabilities and modify fabric configuration or perform other privileged actions, thereby compromising integrity of the network fabric.
Affected Systems
The affected product is Brocade Fabric OS. All releases that precede version 10.0.1 are vulnerable; no newer or patched versions are listed as affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium severity vulnerability. No EPSS score is available, and the issue is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. An attacker must first authenticate to a device using a read‑only account, then send specific management protocol operations that trigger the misclassification. The exploit path requires valid user credentials, but the impact is serious because it allows escalation to full administrative control without additional privileges.
OpenCVE Enrichment