Impact
The vulnerability is an OS command injection in the REST API management interface of Brocade Fabric OS. An attacker who has authenticated, high‑privileged access can supply crafted parameter values containing shell metacharacters. The flaw allows arbitrary system commands to be executed with root permissions, effectively granting full control over the host.
Affected Systems
Affected systems include all Brocade Fabric OS releases prior to 9.2.2d and 10.0.0 through 10.0.0a1. Versions 9.2.2d and 10.0.1 contain the security update that mitigates the issue; earlier releases remain vulnerable.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity and the lack of an EPSS score means exploitation potential cannot be quantified, though the flaw is not listed in CISA KEV. The likely attack path involves an authenticated administrator using the REST API to change SSH known‑host settings; the vulnerability is exploitable remotely from any network location that can reach the API endpoints. Because the affected functionality requires administrative credentials, exploitation is limited to users with high privileges.
OpenCVE Enrichment