Brocade Fabric Os vulnerabilities

30 known vulnerabilities affecting brocade/fabric_os.

Total CVEs
30
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH13MEDIUM16

Vulnerabilities

Page 1 of 2
CVE-2025-58383HIGHCVSS 8.4vbefore 9.2.1c22026-02-03
CVE-2025-58383 [HIGH] CWE-250 CVE-2025-58383: A vulnerability in Brocade Fabric OS versions before 9.2.1c2 could allow an administrator-level user A vulnerability in Brocade Fabric OS versions before 9.2.1c2 could allow an administrator-level user to execute the bind command, to escalate privileges and bypass security controls allowing the execution of arbitrary commands.
cvelistv5nvd
CVE-2025-58382HIGHCVSS 8.5vbefore 9.2.1c2 and 9.2.2 through 9.2.2a2026-02-03
CVE-2025-58382 [HIGH] CWE-305 CVE-2025-58382: A vulnerability in the secure configuration of authentication and management services in Brocade Fa A vulnerability in the secure configuration of authentication and management services in Brocade Fabric OS before Fabric OS 9.2.1c2 could allow an authenticated, remote attacker with administrative credentials to execute arbitrary commands as root using “supportsave”, “seccertmgmt”, “configupload” command.
cvelistv5nvd
CVE-2026-0383HIGHCVSS 8.2vbefore 9.2.1c2, 9.2.2 through 9.2.2a and 10.0.02026-02-03
CVE-2026-0383 [HIGH] CWE-78 CVE-2026-0383: A vulnerability in Brocade Fabric OS could allow an authenticated, local attacker with privileges to A vulnerability in Brocade Fabric OS could allow an authenticated, local attacker with privileges to access the Bash shell to access insecurely stored file contents including the history command.
cvelistv5nvd
CVE-2025-9711HIGHCVSS 8.5vbefore 9.2.1c3, and 9.2.2 though 9.2.2b2026-02-03
CVE-2025-9711 [HIGH] CWE-272 CVE-2025-9711: A vulnerability in Brocade Fabric OS before 9.2.1c3 could allow elevating the privileges of the loca A vulnerability in Brocade Fabric OS before 9.2.1c3 could allow elevating the privileges of the local authenticated user to “root” using the export option of seccertmgmt and seccryptocfg commands.
cvelistv5nvd
CVE-2025-58380MEDIUMCVSS 4.6vbefore 9.2.12026-02-03
CVE-2025-58380 [MEDIUM] CWE-35 CVE-2025-58380: A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin p A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the shell command “grep” to modify the path variables and move upwards in the directory structure or to traverse to different directories.
cvelistv5nvd
CVE-2025-58381MEDIUMCVSS 4.6vbefore 9.2.1c22026-02-03
CVE-2025-58381 [MEDIUM] CWE-35 CVE-2025-58381: A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with adm A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using the shell commands “source, ping6, sleep, disown, wait to modify the path variables and move upwards in the directory structure or to traverse to different directories.
cvelistv5nvd
CVE-2025-58379MEDIUMCVSS 6.0vbefore 9.2.12026-02-03
CVE-2025-58379 [MEDIUM] CWE-250 CVE-2025-58379: Brocade Fabric OS before 9.2.1 has a vulnerability that could allow a local authenticated attacker t Brocade Fabric OS before 9.2.1 has a vulnerability that could allow a local authenticated attacker to reveal command line passwords using commands that may expose higher privilege sensitive information by a lower privileged user.
cvelistv5nvd
CVE-2025-4661MEDIUMCVSS 4.8vBrocade Fabric OS 9.1.0 through 9.2.22025-06-19
CVE-2025-4661 [MEDIUM] CWE-22 CVE-2025-4661: A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain access to files outside the intended directory potentially leading to the disclosure of sensitive information. Note: Admin level privilege is required on the switch in order to exploit
cvelistv5nvd
CVE-2025-1976HIGHCVSS 8.6KEVvFabric OS versions 9.1.0 through 9.1.1d62025-04-24
CVE-2025-1976 [HIGH] CWE-94 CVE-2025-1976: Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.
cvelistv5nvd
CVE-2024-7517HIGHCVSS 8.5vBrocade Fabric OS versions before 9.2.0c, and 9.2.1 through 9.2.1a2024-11-21
CVE-2024-7517 [HIGH] CWE-78 CVE-2024-7517: A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This specific exploitation is only possible on IP Extension platforms: Brocade 7810, Brocade 7840, Brocade 7850 and
cvelistv5nvd
CVE-2024-10403MEDIUMCVSS 5.9vBrocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a2024-11-21
CVE-2024-10403 [MEDIUM] CWE-528 CVE-2024-10403: Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operation initiated by SANnav or through WebEM in a weblinker core dump that is later captured via supportsave.
cvelistv5nvd
CVE-2024-7516HIGHCVSS 7.0vbefore 9.2.22024-11-12
CVE-2024-7516 [HIGH] CWE-322 CVE-2024-7516: A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers t A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking that may arise from the attacker's ability to forge an SSH key while the Brocade Fabric OS Switch is performing various remote operations initiated by a switch admin.
cvelistv5nvd
CVE-2024-5460HIGHCVSS 8.1vprior to v9.0.02024-06-26
CVE-2024-5460 [HIGH] CWE-798 CVE-2024-5460: A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) featu A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could allow an authenticated, remote attacker to read data from an affected device via SNMP. The vulnerability is due to hard-coded, default community string in the configuration file for the SNMP daemon. An a
cvelistv5nvd
CVE-2024-29954MEDIUMCVSS 5.5vbefore v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e2024-06-26
CVE-2024-29954 [MEDIUM] CWE-312 CVE-2024-29954: A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server passwords for protocols such as scp and sftp. Detail. When the firmwaredownload command is incorrectly entered or points to an er
cvelistv5nvd
CVE-2024-29953MEDIUMCVSS 4.3vbefore v9.2.1, v9.2.0b, and v9.1.1d2024-06-26
CVE-2024-29953 [MEDIUM] CWE-922 CVE-2024-29953: A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords.
cvelistv5nvd
CVE-2023-5973MEDIUMCVSS 4.3vVersions v9.x and before v9.2.02024-04-05
CVE-2023-5973 [MEDIUM] CWE-346 CVE-2023-5973: Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade Switch and change ports display.
cvelistv5nvd
CVE-2023-3454CRITICALCVSS 9.8vafter v9.0 and before v9.2.02024-04-04
CVE-2023-3454 [HIGH] CWE-78 CVE-2023-3454: Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could al Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use this to gain root access to the Brocade switch.
cvelistv5nvd
CVE-2023-3489HIGHCVSS 7.5vBrocade Fabric OS v9.2.02023-08-31
CVE-2023-3489 [HIGH] CWE-312 CVE-2023-3489: The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server passwor The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in the SupportSave file when performing a downgrade from Fabric OS v9.2.0 to any earlier version of Fabric OS.
cvelistv5nvd
CVE-2023-4162MEDIUMCVSS 4.4vBrocade Fabric OS after Brocade Fabric OS v9.0 and before Brocade Fabric OS v9.2.0a2023-08-31
CVE-2023-4162 [MEDIUM] CWE-252 CVE-2023-4162: A segmentation fault can occur in Brocade Fabric OS after Brocade Fabric OS v9.0 and before Brocad A segmentation fault can occur in Brocade Fabric OS after Brocade Fabric OS v9.0 and before Brocade Fabric OS v9.2.0a through the passwdcfg command. This could allow an authenticated privileged user local user to crash a Brocade Fabric OS swith using the cli “passwdcfg --set -expire -minDiff“.
cvelistv5nvd
CVE-2023-31432HIGHCVSS 7.8vbefore Brocade Fabric OS v9.1.1c and v9.2.02023-08-02
CVE-2023-31432 [HIGH] CWE-269 CVE-2023-31432: Through manipulation of passwords or other variables, using commands such as portcfgupload, configup Through manipulation of passwords or other variables, using commands such as portcfgupload, configupload, license, myid, a non-privileged user could obtain root privileges in Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c and v9.2.0.
cvelistv5nvd