Impact
An authentication logic flaw in the account management interface of Brocade Fabric OS allows an authenticated user to bypass authorization checks and grant administrative roles to another user. This flaw directly leads to a local privilege escalation where a lower‑privileged account can become a full administrator. The vulnerability is a classic example of improper authorization (CWE‑187).
Affected Systems
The flaw affects Brocade Fabric OS prior to version 9.2.2d and all releases from 10.0.0 through 10.0.0a1. Any installation of these builds that exposes the account management interface to an authenticated user is vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the EPSS score is not available, so the likelihood of exploitation is unclear. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with any level of access; the attack does not need external network access and would typically be carried out by an insider or a compromised account. Once the attacker escalates privileges they can carry out any administrative action on the Fabric OS system.
OpenCVE Enrichment