Impact
A flaw in the internal command‑line interface authorization mechanism of Brocade Fabric OS allows an authenticated user or a local process that can manipulate its process execution environment to bypass role‑based access control. By doing so, an attacker can gain root privileges on the device, compromising confidentiality, integrity and availability of the network fabric.
Affected Systems
The vulnerability affects all Brocade Fabric OS releases prior to 9.2.2d and 10.0.0 through 10.0.0a1. Users running these versions should update to the security releases 9.2.2d or 10.0.1.
Risk and Exploitability
The CVSS score of 7.3 classifies the issue as high severity. EPSS data is not available, indicating limited publicly known exploitation activity. The vulnerability is not listed in the CISA KEV catalog. The attack likely requires local or authenticated access and the ability to alter environment variables or the execution context of the CLI process to subvert RBAC checks.
OpenCVE Enrichment