CVE-2025-4661
- EPSS 0.03%
- Veröffentlicht 19.06.2025 02:27:04
- Zuletzt bearbeitet 23.06.2025 20:16:59
A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain access to files outside the intended directory potentially leading to the disclosure of sensitive information. Note: Admin level pri...
CVE-2025-1976
- EPSS 1.03%
- Veröffentlicht 24.04.2025 03:15:14
- Zuletzt bearbeitet 29.04.2025 19:49:59
Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.
CVE-2024-5461
- EPSS 0.08%
- Veröffentlicht 15.02.2025 00:15:13
- Zuletzt bearbeitet 09.09.2025 19:15:44
Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform command or...
CVE-2024-5462
- EPSS 0.05%
- Veröffentlicht 15.02.2025 00:15:13
- Zuletzt bearbeitet 15.02.2025 00:15:13
If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed in a configupload capture or a ...
CVE-2024-7517
- EPSS 0.22%
- Veröffentlicht 21.11.2024 11:15:35
- Zuletzt bearbeitet 09.09.2025 19:15:45
A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This speci...
CVE-2017-6225
- EPSS 0.52%
- Veröffentlicht 08.02.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:29:18
Cross-site scripting (XSS) vulnerability in the web-based management interface of Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) versions before 7.4.2b, 8.1.2 and 8.2.0 could allow remote attackers to execute arbitrary code or acc...
CVE-2017-6227
- EPSS 0.13%
- Veröffentlicht 08.02.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:29:18
A vulnerability in the IPv6 stack on Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) versions before 7.4.2b, 8.1.2 and 8.2.0 could allow an attacker to cause a denial of service (CPU consumption and device hang) condition by sendin...