Impact
A race condition exists in the REST management interface of Brocade Fabric OS versions prior to 10.0.1. The vulnerability allows an attacker to send multiple FCIP requests concurrently, causing the service to mistakenly associate the response context of one request with the address data of another. This results in the response containing confidential management details or configuration data that truly belong to a different session, thereby exposing sensitive information to the original requester.
Affected Systems
The affected product is Brocade Fabric OS, with all releases before version 10.0.1 susceptible to the race condition. The vendor responsible for the vulnerability is Brocade.
Risk and Exploitability
The CVSS score is 2.1, indicating a low severity impact. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog, implying limited evidence of active exploitation. The likely attack vector is a compromised or malicious host on the same fabric management network able to generate concurrent FCIP REST requests. Successful exploitation requires access to the management interface and the ability to send simultaneous requests; it does not require elevated privileges. The risk is therefore limited to internal threat actors with legitimate network access who can exploit timing differences to receive data from other sessions.
OpenCVE Enrichment