CVE-2024-7517

Severity
8.5HIGH
EPSS
0.1%
top 68.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 21
Latest updateSep 9

Description

A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This specific exploitation is only possible on IP Extension platforms: Brocade 7810, Brocade 7840, Brocade 7850 and on Brocade X6 or X7 directors with an SX-6 Extension blade installed. The attacker must be logged into the switch via SSH or serial console to c

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5brocade/fabric_osBrocade Fabric OS versions before 9.2.0c, and 9.2.1 through 9.2.1a
NVDbroadcom/fabric_operating_system9.2.19.2.1a+1

🔴Vulnerability Details

2
GHSA
GHSA-89mq-4fx7-3g3c: A command injection vulnerability in Brocade Fabric OS before 92025-09-09
CVEList
Privileged escalation via crafted use of portcfg command2024-11-21
CVE-2024-7517 (HIGH CVSS 8.5) | A command injection vulnerability i | cvebase.io