Skip to main content

Vendor/product archive

broadcom / fabric_operating_system CVEs

Beta · best-effort

95 CVEs tagged to broadcom / fabric_operating_system8 Critical, 45 High, 41 Medium, 1 Low, 0 Unrated.

CVE-2025-9711

Published Feb 3, 2026

A vulnerability in Brocade Fabric OS before 9.2.1c3 could allow elevating the privileges of the local authenticated user to “root” using the export option of seccertmgmt and seccr…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58381

Published Feb 3, 2026

A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using the shell commands “source, ping6, sleep, disown, wait to…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-58380

Published Feb 3, 2026

A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the shell command “grep” to modify the path variables and move…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-0383

Published Feb 3, 2026

A vulnerability in Brocade Fabric OS could allow an authenticated, local attacker with privileges to access the Bash shell to access insecurely stored file contents including the…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-58383

Published Feb 3, 2026

A vulnerability in Brocade Fabric OS versions before 9.2.1c2 could allow an administrator-level user to execute the bind command, to escalate privileges and bypass security contro…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58382

Published Feb 3, 2026

A vulnerability in the secure configuration of authentication and management services in Brocade Fabric OS before Fabric OS 9.2.1c2 could allow an authenticated, remote attacker…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58379

Published Feb 3, 2026

Brocade Fabric OS before 9.2.1 has a vulnerability that could allow a local authenticated attacker to reveal command line passwords using commands that may expose higher privilege…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-4663

Published Jul 8, 2025

An Improper Check for Unusual or Exceptional Conditions vulnerability in Brocade Fabric OS before 9.2.2.a could allow an authenticated, network-based attacker to cause a Denial…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-4661

Published Jun 19, 2025

A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain access to files outside the intended directory potentially leadi…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1976

Published Apr 24, 2025

Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privilege…

CVSS 8.6 · High
evidence mentions
7
Buzz score
65.3
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-5462

Published Feb 15, 2025

If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext.…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7517

Published Nov 21, 2024

A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a pr…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10403

Published Nov 21, 2024

Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operati…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7516

Published Nov 12, 2024

A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking that may arise from the attacker's a…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5460

Published Jun 26, 2024

A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could allow an authenticated, r…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-29954

Published Jun 26, 2024

A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29953

Published Jun 26, 2024

A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. Th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5973

Published Apr 5, 2024

Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3454

Published Apr 4, 2024

Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use this to gain root access to t…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27795

Published Dec 6, 2023

Brocade Fabric OS (FOS) hardware platforms running any version of Brocade Fabric OS software, which supports the license string format; contain cryptographic issues that could…

CVSS 6.4 · Medium

CVE-2023-4163

Published Aug 31, 2023

In Brocade Fabric OS before v9.2.0a, a local authenticated privileged user can trigger a buffer overflow condition, leading to a kernel panic with large input to buffers in the…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 95 CVEsPage 1 of 4