Impact
A logic vulnerability in the web management framework of Brocade Fabric OS allows an authenticated user with low privileges to bypass internal Role-Based Access Control (RBAC) checks under certain environmental conditions. By exploiting this flaw, the attacker can lower the authorization mode for the active session and gain access to configuration settings that are normally restricted to administrative roles. The CVSS score of 6.9 reflects that the vulnerability can lead to unauthorized configuration changes, impacting confidentiality, integrity, and availability of the fabric management environment.
Affected Systems
The flaw exists in all Brocade Fabric OS releases prior to version 10.0.1. Only the 10.0.1 release or later contains the remediation that eliminates the RBAC bypass logic. Critical systems running older Fabric OS should be verified for this vulnerability.
Risk and Exploitability
The vulnerability requires the attacker to be authenticated and possess a low‑privilege account; it does not provide remote code execution. The impact is limited to elevated privileges within the management session, but can change critical configuration settings. Because no EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is uncertain; however, the attack vector is internal or via the web interface, making it relevant to environments where web management access is granted to non‑admin users. Rapid patching is therefore recommended to prevent potential privilege escalation.
OpenCVE Enrichment