Brocade Fabric OS
cpe:2.3:o:broadcom:brocade_fabric_operating_system:*:*:*:*:*:*:*, +4 more
- >= 9.1.0, <= 9.1.1d6
This vulnerability is being actively exploited in the wild.
A code injection vulnerability has been identified in Brocade Fabric OS versions 9.1.0 through 9.1.1d6. In these versions, root access has been removed, but a local user with admin privileges can execute arbitrary code with full root rights. This exploitation takes advantage of a flaw in IP address validation, allowing the user to run any existing Fabric OS command or modify the operating system by adding custom subroutines. Although this vulnerability requires valid access to an admin role, it has been actively exploited in the field.
Exploitation of this vulnerability allows for arbitrary code execution with root privileges on the affected system.
Users are advised to upgrade to Brocade Fabric OS version 9.1.1d7, which addresses this vulnerability. For those using versions prior to 9.1.0, the switch ADMIN role can directly access root, so an upgrade to a version that removes root access is recommended where possible.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.