Impact
An OS command injection flaw exists in the PAM session cleanup routines of Brocade Fabric OS. If an authenticated user authenticates via an external directory or AAA service and their username or profile identifier contains shell metacharacters, the service will inject those characters into an OS command executed during SSH session termination. This results in arbitrary command execution with root privileges when the remote SSH session closes.
Affected Systems
Brocade Fabric OS versions prior to 9.2.2d and the 10.0.0 through 10.0.0a1 releases are affected. Older 9.x releases before 9.2.2d also have the vulnerability.
Risk and Exploitability
The CVSS score is 5.4, indicating moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user to create or modify a username or profile identifier that includes shell metacharacters, typically through the external directory or AAA service. When the user logs out via SSH, the PAM cleanup routine executes the malformed command as root, granting the attacker arbitrary root‑level command execution on the Fabric OS host.
OpenCVE Enrichment