Impact
The flaw resides in the web dispatcher routine of Brocade Fabric OS, where the system incorrectly uses the client‑supplied HTTP Host header instead of the source IP when determining internal management VLAN trust. This oversight enables an attacker to bypass ACLs on the management interface and pull device metadata—including model, serial number, hardware revision, and firmware version—without any authentication. Once an adversary gains this device information, they can target the appliance for further attacks.
Affected Systems
Devices running Brocade Fabric OS versions earlier than 10.0.1 are impacted. The vulnerability is in the web server management interface and applies to any deployment that relies on the default internal management VLAN trust settings.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score is not available. The flaw is not listed in the CISA KEV catalog. Exploitation requires a crafted HTTP request with a manipulated Host header sent to the management web server, and no authentication is necessary. Although the attack surface is limited to the management interface, the ability to obtain device details without authentication poses a significant risk for targeted post‑exploitation efforts.
OpenCVE Enrichment