Impact
The vulnerability is a stack‑based buffer overflow in the REST API management component of Brocade Fabric OS. When the service processes API requests, it does not correctly check array sizes or string lengths against internal buffer limits, allowing an authenticated attacker with REST API access to send oversized payloads. This can corrupt the execution stack, potentially causing a denial‑of‑service through a daemon crash or enabling the attacker to execute arbitrary code within the management process context. The flaw aligns with CWE‑121, indicating an improper handling of buffer bounds.
Affected Systems
Brocade Fabric OS versions prior to 10.0.1 are affected. This includes all deployments running Fabric OS below the 10.0.1 release, regardless of configuration or additional modules. The advisory does not specify narrower version ranges, so the entire pre‑10.0.1 set should be considered vulnerable.
Risk and Exploitability
The CVSS score of 8.6 marks the issue as high severity. While the EPSS score is not available, the potential for arbitrary code execution and the requirement of only authenticated REST API access make exploitation plausible in environments where administrators or malicious users can access the API. The vulnerability is not listed in the CISA KEV catalog, but its severity and exploitability still warrant immediate attention. An attacker would typically proceed by authenticating to the REST API, crafting a request with excessive array or string parameters, and transmitting it to trigger the overflow. Successful exploitation could lead to service disruption or full compromise of the management process.
OpenCVE Enrichment