Impact
A stack-based buffer overflow exists in the SNMP daemon of Brocade Fabric OS versions prior to 10.0.1. When a SNMPv3 packet is received, the daemon copies user-supplied context name data into a fixed-size buffer without properly validating the string length. This leads to memory corruption that can cause the daemon to crash or, in worst case, allow an attacker to execute arbitrary code. The vulnerability can be abused by a remote and unauthenticated attacker, so the impact covers confidentiality, integrity, and availability of the affected device.
Affected Systems
Brocade Fabric OS versions earlier than 10.0.1 are affected. The flaw is present in the SNMP daemon component of these operating system releases.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker sending a crafted SNMPv3 packet to the device, potentially under default configuration. No authentication or minimal authentication is required, making exploitation highly feasible if exposed to the network.
OpenCVE Enrichment