Description
A buffer overflow vulnerability exists in the WebTools administrative interface handling configuration download or file transfer operations of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with permissions to perform configuration downloads using remote server profiles can overflow stack buffers causing a crash of the weblinker daemon.
Published: 2026-10-08
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Stack buffer overflow causing service crash
Action: Apply Patch
AI Analysis

Impact

A buffer overflow exists in the WebTools administrative interface when handling configuration downloads or file transfer operations on Brocade Fabric OS before specific updates. The flaw, classified as CWE-120, allows an authenticated user with permission to perform configuration downloads from remote server profiles to overflow stack buffers. This overflow does not grant code execution but crashes the weblinker daemon, disrupting the web interface and resulting in a denial‑of‑service condition.

Affected Systems

The vulnerability affects Brocade Fabric OS versions prior to 9.2.2d and the 10.0.0 series up to 10.0.0a1. Users running these firmware releases are at risk if they have the aforementioned privileged permissions on the WebTools interface.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires valid credentials and the ability to initiate configuration download operations, so attackers must first compromise or be granted privileged user access. Because it leads only to a crash of the weblinker daemon, the impact is primarily a denial of service rather than data compromise or remote code execution. Prompt application of the vendor‑supplied security updates is the most effective countermeasure.

Generated by OpenCVE AI on October 8, 2026 at 06:23 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 9.2.2d and 10.0.1


OpenCVE Recommended Actions

  • Upgrade Brocade Fabric OS to version 9.2.2d or 10.0.1 to apply the vendor‑provided fix
  • Restrict the use of configuration download from remote server profiles to the minimum number of trusted accounts
  • If the WebTools interface is not required, disable or block access to it to prevent exposure to the vulnerability

Generated by OpenCVE AI on October 8, 2026 at 06:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Brocade Fabric OS WebTools Administrative Interface

Thu, 08 Oct 2026 05:00:00 +0000

Type Values Removed Values Added
Description A buffer overflow vulnerability exists in the WebTools administrative interface handling configuration download or file transfer operations of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with permissions to perform configuration downloads using remote server profiles can overflow stack buffers causing a crash of the weblinker daemon.
Weaknesses CWE-120
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T04:37:56.646Z

Reserved: 2026-09-21T20:30:23.102Z

Link: CVE-2026-94587

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T05:17:06.890

Modified: 2026-10-08T05:17:06.890

Link: CVE-2026-94587

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T06:30:17Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')