Impact
An authenticated user with USB management privileges can craft REST API requests that manipulate target paths, allowing deletion of arbitrary files or directories beyond the intended USB mount point boundaries. This flaw permits loss of critical configuration or data files and compromises the integrity of the switch’s local root filesystem, potentially leading to disruption of network operations.
Affected Systems
The issue affects Brocade Fabric OS versions prior to 10.0.1. Any device running a vulnerable Fabric OS build that exposes the USB storage REST API to authenticated users is at risk.
Risk and Exploitability
The vulnerability scores a CVSS base of 5.7, indicating moderate severity. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog, suggesting no publicly known exploit at present. However, the flaw requires authenticated access with specific USB management rights, so exposure risk depends on the security of user credentials and privilege controls. If an attacker gains such credentials, they can delete critical files, potentially causing denial of service or enabling further attacks against the network.
OpenCVE Enrichment