VendorsBroadcomfabric_operating_systemall versions
Vulnerabilities

Broadcom Fabric Operating System (FOS)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

95CVEs
CVE-2019-18805
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen, leading to a denial of service or possibly unspecified other impact, aka CID-19fad20d15a6.
Published 2019-11-07 · Modified
9.8EPSS 0.034
CVE-2020-15373
Multiple buffer overflow vulnerabilities in REST API in Brocade Fabric OS versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c could allow remote unauthenticated attackers to perform various attacks.
Published 2020-09-25 · Modified
9.8EPSS 0.024
CVE-2022-33186
A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric OS switch commands capable of modifying zoning, disabling the switch, disabling ports, and modifying the switch IP address.
Published 2022-12-08 · Modified
9.8EPSS 0.016
CVE-2021-27797
Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain access to the system.
Published 2022-02-21 · Modified
9.8EPSS 0.013
CVE-2020-15371
Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, contains code injection and privilege escalation vulnerability.
Published 2020-09-25 · Modified
9.8EPSS 0.013
CVE-2020-15374
Rest API in Brocade Fabric OS v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c is vulnerable to multiple instances of reflected input.
Published 2020-09-25 · Modified
9.8EPSS 0.012
CVE-2023-3454
Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use this to gain root access to the Brocade switch.
Published 2024-04-04 · Modified
9.8EPSS 0.012
CVE-2018-6440
A vulnerability in the proxy service of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow remote unauthenticated attackers to obtain sensitive information and possibly cause a denial of service attack.
Published 2018-12-03 · Modified
9.1EPSS 0.022
CVE-2024-3596
RADIUS Protocol under RFC2865 is vulnerable to forgery attacks.
Published 2024-07-09 · Modified
9.0EPSS 0.149
CVE-2016-8202
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected versions, non-root users can gain root access with a combination of shell commands and parameters.
Published 2017-05-08 · Modified
9.0EPSS 0.031
CVE-2018-6442
A vulnerability in the Brocade Webtools firmware update section of Brocade Fabric OS before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow remote authenticated attackers to execute arbitrary commands.
Published 2018-11-08 · Modified
8.8EPSS 0.021
CVE-2022-33183
A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a remote authenticated attacker to perform stack buffer overflow using in “firmwaredownload” and “diagshow” commands.
Published 2022-10-25 · Modified
8.8EPSS 0.015
CVE-2020-15369
Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c does not obfuscate the password field, which could expose users’ credentials of the remote server. An authenticated user could obtain the exposed password credentials to gain access to the remote host.
Published 2020-09-25 · Modified
8.8EPSS 0.010
CVE-2022-28169
Brocade Webtools in Brocade Fabric OS versions before Brocade Fabric OS versions v9.1.1, v9.0.1e, and v8.2.3c could allow a low privilege webtools, user, to gain elevated admin rights, or privileges, beyond what is intended or entitled for that user. By exploiting this vulnerability, a user whose role is not an admin can create a new user with an admin role using the operator session id. The issue was replicated after intercepting the admin, and operator authorization headers sent unencrypted and editing a user addition request to use the operator's authorization header.
Published 2022-10-25 · Modified
8.8EPSS 0.008
CVE-2022-33179
A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, and 7.4.2j could allow a local authenticated user to break out of restricted shells with “set context” and escalate privileges.
Published 2022-10-25 · Modified
8.8EPSS 0.002
CVE-2025-1976
Code injection exposure in Fabric OS 9.1.0 through 9.1.1d6
Published 2025-04-24 · Analyzed
8.6KEVEPSS 0.007
CVE-2024-5461
Command or parameter injection via unique embedded switch SNMP commands.
Published 2025-02-15 · Analyzed
8.6EPSS 0.005
CVE-2023-3489
firmwaredownload command could log servers passwords in clear text
Published 2023-08-30 · Modified
8.6EPSS 0.004
CVE-2024-7517
Privileged escalation via crafted use of portcfg command
Published 2024-11-21 · Analyzed
8.5EPSS 0.006
CVE-2025-58382
Privilege escalation in Brocade Fabric before 9.2.1c2 and 9.2.2 through 9.2.2a
Published 2026-02-03 · Analyzed
8.5EPSS 0.006
CVE-2025-9711
Privilege escalation in Brocade Fabric OS before 9.2.1c3, and 9.2.2 though 9.2.2b
Published 2026-02-03 · Analyzed
8.5EPSS 0.001
CVE-2025-58383
Privilege escalation via bind command in Brocade Fabric OS
Published 2026-02-03 · Analyzed
8.4EPSS 0.005
CVE-2026-0383
Information disclosure in Brocade Fabric OS before 9.2.1c2, 9.2.2 through 9.2.2a and 10.0.0
Published 2026-02-03 · Analyzed
8.2EPSS 0.002
CVE-2024-5460
Brocade Fabric OS versions prior to v9.0 have default community strings
Published 2024-06-25 · Analyzed
8.1EPSS 0.005
CVE-2021-27795
License forgery in Brocade Fabric OS (FOS) hardware platforms running any version of Brocade Fabric OS software,
Published 2023-12-06 · Modified
8.1EPSS 0.002
CVE-2020-15778
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
Published 2020-07-24 · Analyzed
7.8EPSS 0.130
CVE-2019-19050
A memory leak in the crypto_reportstat() function in crypto/crypto_user_stat.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_reportstat_alg() failures, aka CID-c03b04dcdba1.
Published 2019-11-18 · Modified
7.8EPSS 0.051
CVE-2019-19069
A memory leak in the fastrpc_dma_buf_attach() function in drivers/misc/fastrpc.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering dma_get_sgtable() failures, aka CID-fc739a058d99.
Published 2019-11-18 · Modified
7.8EPSS 0.035
CVE-2016-4376
HPE FOS before 7.4.1d and 8.x before 8.0.1 on StoreFabric B switches allows remote attackers to obtain sensitive information via unspecified vectors.
Published 2016-08-22 · Modified
7.8EPSS 0.022
CVE-2020-29661
A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b.
Published 2020-12-09 · Modified
7.8EPSS 0.011
CVE-2021-27790
The command ipfilter in Brocade Fabric OS before Brocade Fabric OS v.9.0.1a, v8.2.3, and v8.2.0_CBN4, and v7.4.2h uses unsafe string function to process user input. Authenticated attackers can abuse this vulnerability to exploit stack-based buffer overflows, allowing execution of arbitrary code as the root user account.
Published 2021-08-12 · Modified
7.8EPSS 0.005
CVE-2018-6441
A vulnerability in Secure Shell implementation of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to provide arbitrary environment variables, and bypass the restricted configuration shell.
Published 2018-11-08 · Modified
7.8EPSS 0.004
CVE-2018-6438
A Vulnerability in the supportsave command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, gain root access.
Published 2018-11-08 · Modified
7.8EPSS 0.004
CVE-2018-6436
A Vulnerability in the firmwaredownload command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, gain root access.
Published 2018-11-08 · Modified
7.8EPSS 0.004
CVE-2018-6437
A Vulnerability in the help command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, gain root access.
Published 2018-11-08 · Modified
7.8EPSS 0.004
CVE-2018-6435
A Vulnerability in the secryptocfg command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, and gain root access.
Published 2018-11-08 · Modified
7.8EPSS 0.004
CVE-2018-6439
A Vulnerability in the configdownload command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, gain root access.
Published 2018-12-03 · Modified
7.8EPSS 0.003
CVE-2022-33184
A vulnerability in fab_seg.c.h libraries of all Brocade Fabric OS versions before Brocade Fabric OS v9.1.1, v9.0.1e, v8.2.3c, v8.2.0_cbn5, 7.4.2j could allow local authenticated attackers to exploit stack-based buffer overflows and execute arbitrary code as the root user account.
Published 2022-10-25 · Modified
7.8EPSS 0.003
CVE-2022-33185
Several commands in Brocade Fabric OS before Brocade Fabric OS v.9.0.1e, and v9.1.0 use unsafe string functions to process user input. Authenticated local attackers could abuse these vulnerabilities to exploit stack-based buffer overflows, allowing arbitrary code execution as the root user account.
Published 2022-10-25 · Modified
7.8EPSS 0.003
CVE-2023-31425
Privilege escalation via the fosexec command
Published 2023-08-01 · Modified
7.8EPSS 0.003
1 / 3Next →