Impact
An authenticated administrative user can submit a crafted status file path to the Fabric OS WebTools interface, causing the system to move an arbitrary file to a predictable, world‑readable temporary location. This flaw permits persistent denial of service, deliberate deletion of critical system files, host compromise, or leakage of sensitive data by granting the attacker control over file placement and visibility.
Affected Systems
The vulnerability is present in Brocade Fabric OS versions before 9.2.2d and from 10.0.0 through 10.0.0a1, affecting only installations that expose the WebTools management interface. The known fix is provided in Fabric OS 9.2.2d and 10.0.1.
Risk and Exploitability
The flaw carries a CVSS score of 8.4 and currently has no EPSS data, and it is not listed in the CISA KEV catalog. Exploitation requires an authenticated administrator, after which the attacker can move files to world‑readable directories, facilitating denial of service, file corruption, or information disclosure. The high severity and privileged‑authentication prerequisite place significant risk on environments where admin interfaces are exposed.
OpenCVE Enrichment