Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.
History

Tue, 29 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Broadcom
Broadcom fabric Operating System
Weaknesses CWE-78
CPEs cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:*
Vendors & Products Broadcom
Broadcom fabric Operating System
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Mon, 28 Apr 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2025-04-28'}


Mon, 28 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 24 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 24 Apr 2025 03:15:00 +0000

Type Values Removed Values Added
Description Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.
Title Code injection exposure in Fabric OS 9.1.0 through 9.1.1d6
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published: 2025-04-24T02:55:40.225Z

Updated: 2025-04-30T03:56:19.141Z

Reserved: 2025-03-04T23:23:05.671Z

Link: CVE-2025-1976

cve-icon Vulnrichment

Updated: 2025-04-24T13:03:58.280Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-24T03:15:14.820

Modified: 2025-04-29T19:49:59.680

Link: CVE-2025-1976

cve-icon Redhat

No data.