Impact
A buffer overflow exists in the internal diagnostic and route validation routines of Brocade Fabric OS prior to 10.0.1. This flaw allows incoming or internally routed diagnostic state payloads to exceed allocated memory boundaries, which can lead to a heap- or stack-based memory overrun. When successfully exploited, the routing daemon can crash, resulting in a denial of service, or the attacker may achieve arbitrary code execution within the daemon’s context.
Affected Systems
Brocade Fabric OS versions below 10.0.1, specifically the Fabric Shortest Path First (FSPF) component. All installations of Fabric OS pre‑10.0.1 are vulnerable; the security update starting in 10.0.1 resolves the defect.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity. Because the affected code path is not exposed via standard user interfaces, an attacker would need to chain this flaw with another weakness or gain internal diagnostic access to trigger the overflow. No KEV listing or known exploit campaigns exist, and EPSS is not available, suggesting exploitation likelihood is low for isolated systems. Nonetheless, the potential for denial of service or code execution warrants prompt mitigation.
OpenCVE Enrichment