CVE-2026-87673: fallo de gravedad alta en Brocade Fabric OS
Publicada el
18Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
An OS command injection vulnerability exists in maintenance command-line diagnostic utilities on Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. The binary fails to sanitize user-supplied input options when invoking underlying system commands through a shell interpreter. A privileged user with maintenance account access can exploit this issue by supplying crafted parameters, which results in arbitrary OS command execution with root privileges.
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
Brocade · Fabric OSCVEs relacionadas — Brocade Fabric OS
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-1976HIGHCode injection exposure in Fabric OS 9.1.0 through 9.1.1d6EPSS 0.7%KEVCVE-2023-3454HIGHCVE-2023-3454EPSS 1.2%CVE-2024-10403MEDIUMSFTP/FTP password could be captured in plain text in Supportsave generated from SANnavEPSS 0.7%CVE-2025-58382HIGHPrivilege escalation in Brocade Fabric before 9.2.1c2 and 9.2.2 through 9.2.2aEPSS 0.6%CVE-2023-31927MEDIUMAn information disclosure in the web interface of Brocade Fabric OSEPSS 0.6%CVE-2024-7517HIGHPrivileged escalation via crafted use of portcfg commandEPSS 0.6%