PT-2025-6717 · Brocade · Brocade 6547
Pierre Barre
·
Published
2025-02-15
·
Updated
2026-02-23
·
CVE-2024-5461
CVSS v4.0
8.6
High
| Vector | AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Brocade 6547 (FC5022) versions prior to 8.2.3e1 pha
Description
The implementation of the Simple Network Management Protocol (SNMP) in the Brocade 6547 (FC5022) embedded switch blade makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform command or parameter injection on SNMP operations, allowing them to issue commands as Root.
Recommendations
For Brocade 6547 (FC5022) versions prior to 8.2.3e1 pha, update to version 8.2.3e1 pha or later to resolve the issue. As a temporary workaround, consider restricting access to SNMP operations to minimize the risk of exploitation.
Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Brocade 6547