Impact
An input validation flaw exists in the certificate management component of the Brocade Fabric OS administrative API. When a user supplies a certificate identifier, the value is not properly sanitized before being passed to external system routines. An attacker who is authenticated and has permission to delete certificates can exploit this weakness to execute arbitrary system commands with the privileges of the underlying management daemon, potentially compromising the entire Fabric OS environment.
Affected Systems
Brocade Fabric OS is affected. Versions prior to 9.2.2d for the 9.x line and all 10.0.0 releases up to 10.0.0a1 for the 10.x line are vulnerable. The patch series 9.2.2d and 10.0.1 address the issue.
Risk and Exploitability
The flaw carries a CVSS score of 8.5, indicating high severity. No EPSS score is published, and the vulnerability is not listed in CISA’s KEV catalog. Because an authenticated attacker can obtain command‑execution privileges, the risk is significant for systems with exposed management APIs. The likely attack vector involves a legitimate user executing a deletion request, which the system processes without sanitizing the identifier.
OpenCVE Enrichment