CVE-2026-87671: fallo de gravedad alta en Brocade Fabric OS
Publicada el
18Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.1
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
An out-of-bounds memory read vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1. Unauthenticated HTTP endpoints process specific URL query parameters without validating array index boundaries or performing numerical range checks. An unauthenticated remote attacker can exploit this issue by sending a single, crafted HTTP request containing extreme numerical values in the query string. This causes an invalid memory dereference, resulting in a crash of the web management process (Denial of Service) and potential temporary management-plane disruption.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Productos afectados
Brocade · Fabric OSCVEs relacionadas — Brocade Fabric OS
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-1976HIGHCode injection exposure in Fabric OS 9.1.0 through 9.1.1d6EPSS 0.7%KEVCVE-2023-3454HIGHCVE-2023-3454EPSS 1.2%CVE-2024-10403MEDIUMSFTP/FTP password could be captured in plain text in Supportsave generated from SANnavEPSS 0.7%CVE-2025-58382HIGHPrivilege escalation in Brocade Fabric before 9.2.1c2 and 9.2.2 through 9.2.2aEPSS 0.6%CVE-2023-31927MEDIUMAn information disclosure in the web interface of Brocade Fabric OSEPSS 0.6%CVE-2024-7517HIGHPrivileged escalation via crafted use of portcfg commandEPSS 0.6%