Impact
An authentication bypass flaw resides in the web management interface of Brocade Fabric OS on the MXG610 platform. The vulnerability allows a user without valid credentials to reach an unauthenticated endpoint in the Single Sign‑On workflow and gain full administrative control of the device’s management interface. This flaw exposes the attacker the ability to modify configuration, deploy new services, or redirect traffic, thereby compromising confidentiality, integrity, and availability of the platform.
Affected Systems
The issue affects Brocade Fabric OS versions prior to 9.2.2d. The affected product is the MXG610 series operating under Fabric OS 9.x or earlier, including all builds before 9.2.2d. Updates are available in Fabric OS 9.2.2d and 10.0.1, which correct the authentication weakness.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity. The EPSS score is not available, so the probability of exploitation cannot be quantified with current data. The vulnerability is not listed in the CISA KEV catalog. An attacker who is directly connected to the device’s network—i.e., a network‑adjacent threat—can exploit the unauthenticated SSO endpoint using publicly accessible web requests, making the attack vector nature local or internal.
OpenCVE Enrichment