PT-2025-17487 · Brocade · Brocade Fabric Os
Published
2025-04-17
·
Updated
2025-06-03
·
CVE-2025-1976
CVSS v4.0
8.6
High
| Vector | AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Brocade Fabric OS versions 9.1.0 through 9.1.1d6
Description
The issue allows a local user with admin privilege to potentially execute arbitrary code with full root privileges. This is a critical vulnerability that has been actively exploited. A local admin user can gain root access via code injection. The estimated number of potentially affected devices is not specified.
Recommendations
For Brocade Fabric OS versions 9.1.0 through 9.1.1d6, patch immediately to prevent code injection and limit SAN management access to minimize the risk of exploitation. As a temporary workaround, consider restricting access to sensitive areas of the system until a patch is available.
Fix
LPE
Code Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Brocade Fabric Os