Impact
An authentication bypass coupled with inadequate input validation in Brocade Fabric OS permits a user who has been granted only limited privileges within a single Virtual Fabric to issue a specially crafted request that references another fabric identifier. The vulnerability, categorized as CWE-88, enables the attacker to carry out unauthorized operations across fabrics and to read configuration information that should be inaccessible. The affected user can effectively gain the same capabilities and visibility as a higher‑privileged administrator within the target fabric.
Affected Systems
The flaw impacts all versions of Brocade Fabric OS prior to 9.2.2d and 10.0.0 through 10.0.0a1. Any deployment running one of these releases is susceptible, regardless of the number of virtual fabrics configured.
Risk and Exploitability
The CVSS score of 8.5 indicates a high‑severity exploitation risk. While the EPSS score is not reported, the lack of a KEV listing suggests no publicly known exploits yet. The attack requires the attacker to be authenticated with restricted privileges in a virtual fabric, after which a crafted request can be sent to trigger the cross‑fabric access. Given the absence of a widely known exploit, the likelihood of immediate compromise is moderate, but the potential impact warrants timely remediation.
OpenCVE Enrichment