PT-2025-17487 · Brocade · Brocade Fabric Os

Published

2025-04-17

·

Updated

2025-06-03

·

CVE-2025-1976

CVSS v4.0

8.6

High

VectorAV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Brocade Fabric OS versions 9.1.0 through 9.1.1d6
Description The issue allows a local user with admin privilege to potentially execute arbitrary code with full root privileges. This is a critical vulnerability that has been actively exploited. A local admin user can gain root access via code injection. The estimated number of potentially affected devices is not specified.
Recommendations For Brocade Fabric OS versions 9.1.0 through 9.1.1d6, patch immediately to prevent code injection and limit SAN management access to minimize the risk of exploitation. As a temporary workaround, consider restricting access to sensitive areas of the system until a patch is available.

Fix

LPE

Code Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-04740
CVE-2025-1976

Affected Products

Brocade Fabric Os