Impact
Multiple OS command injection flaws have been identified in Brocade Fabric OS management interfaces and session processing. The weaknesses allow untrusted input containing shell metacharacters to reach internal execution wrappers. An attacker with authenticated account privileges, or one who has compromised a directory service account, can exploit these vulnerabilities to run arbitrary operating‑system commands with elevated rights on the device.
Affected Systems
Affected products are Brocade Fabric OS versions prior to 10.0.1. Any deployment running an earlier release is vulnerable; newer releases contain the security update.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.6, indicating high severity. EPSS data is not available and the issue is not listed in the CISA KEV catalog. The attack vector requires authentication or a compromised directory account, meaning that a legitimate user or a malicious actor who has stolen credentials can execute arbitrary commands remotely.
OpenCVE Enrichment