Impact
A buffer overflow exists in the WebTools administrative interface when handling configuration downloads or file transfer operations on Brocade Fabric OS before specific updates. The flaw, classified as CWE-120, allows an authenticated user with permission to perform configuration downloads from remote server profiles to overflow stack buffers. This overflow does not grant code execution but crashes the weblinker daemon, disrupting the web interface and resulting in a denial‑of‑service condition.
Affected Systems
The vulnerability affects Brocade Fabric OS versions prior to 9.2.2d and the 10.0.0 series up to 10.0.0a1. Users running these firmware releases are at risk if they have the aforementioned privileged permissions on the WebTools interface.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires valid credentials and the ability to initiate configuration download operations, so attackers must first compromise or be granted privileged user access. Because it leads only to a crash of the weblinker daemon, the impact is primarily a denial of service rather than data compromise or remote code execution. Prompt application of the vendor‑supplied security updates is the most effective countermeasure.
OpenCVE Enrichment