VendorsBroadcomfabric_operating_systemall versions
Vulnerabilities

Broadcom Fabric Operating System (FOS)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

95CVEs
CVE-2021-27792
The request handling functions in web management interface of Brocade Fabric OS versions before v9.0.1a, v8.2.3a, and v7.4.2h do not properly handle malformed user input, resulting in a service crash. An authenticated attacker could use this weakness to cause the FOS HTTP application handler to crash, requiring a reboot.
Published 2021-08-12 · Modified
7.8EPSS 0.003
CVE-2021-27794
A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a and v7.4.2h could allow a user to Login with empty password, and invalid password through telnet, ssh and REST.
Published 2021-08-12 · Modified
7.8EPSS 0.002
CVE-2023-31427
Knowledge of full path name
Published 2023-08-01 · Modified
7.8EPSS 0.002
CVE-2022-33182
A privilege escalation vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, could allow a local authenticated user to escalate its privilege to root using switch commands “supportlink”, “firmwaredownload”, “portcfgupload, license, and “fosexec”.
Published 2022-10-25 · Modified
7.8EPSS 0.002
CVE-2020-1967
Segmentation fault in SSL_check_chain
Published 2020-04-21 · Modified
7.5EPSS 0.533
CVE-2019-16204
Brocade Fabric OS Versions before v7.4.2f, v8.2.2a, v8.1.2j and v8.2.1d could expose external passwords, common secrets or authentication keys used between the switch and an external server.
Published 2020-02-05 · Modified
7.5EPSS 0.015
CVE-2018-6448
A vulnerability in the management interface in Brocade Fabric OS Versions before Brocade Fabric OS v9.0.0 could allow a remote attacker to perform a denial of service attack on the vulnerable host.
Published 2020-09-25 · Modified
7.5EPSS 0.014
CVE-2019-16203
Brocade Fabric OS Versions before v8.2.2a and v8.2.1d could expose the credentials of the remote ESRS server when these credentials are given as a command line option when configuring the ESRS client.
Published 2020-02-05 · Modified
7.5EPSS 0.014
CVE-2018-6434
A vulnerability in the web management interface of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow attackers to intercept or manipulate a user's session ID.
Published 2018-11-08 · Modified
7.5EPSS 0.012
CVE-2020-15383
Running security scans against the SAN switch can cause config and secnotify processes within the firmware before Brocade Fabric OS v9.0.0, v8.2.2d and v8.2.1e to consume all memory leading to denial of service impacts possibly including a switch panic.
Published 2021-06-09 · Modified
7.5EPSS 0.010
CVE-2024-10403
SFTP/FTP password could be captured in plain text in Supportsave generated from SANnav
Published 2024-11-21 · Analyzed
7.5EPSS 0.007
CVE-2024-5462
Brocade Fabric OS may capture SNMP Passwords in clear text
Published 2025-02-14 · Analyzed
7.5EPSS 0.002
CVE-2020-15387
The host SSH servers of Brocade Fabric OS before Brocade Fabric OS v7.4.2h, v8.2.1c, v8.2.2, v9.0.0, and Brocade SANnav before v2.1.1 utilize keys of less than 2048 bits, which may be vulnerable to man-in-the-middle attacks and/or insecure SSH communications.
Published 2021-06-09 · Modified
7.4EPSS 0.005
CVE-2023-38709
Apache HTTP Server: HTTP response splitting
Published 2024-04-04 · Modified
7.3EPSS 0.039
CVE-2022-33178
A vulnerability in the radius authentication system of Brocade Fabric OS before Brocade Fabric OS 9.0 could allow a remote attacker to execute arbitrary code on the Brocade switch.
Published 2022-10-25 · Modified
7.2EPSS 0.014
CVE-2019-25013
The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.
Published 2021-01-04 · Modified
7.1EPSS 0.035
CVE-2024-7516
Brocade Fabric OS before 9.2.2 does not enforce strict host key checking
Published 2024-11-12 · Analyzed
7.1EPSS 0.003
CVE-2019-18683
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are multiple race conditions during streaming stopping in this driver (part of the V4L2 subsystem). These issues are caused by wrong mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(), sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these race conditions leads to a use-after-free.
Published 2019-11-04 · Modified
7.0EPSS 0.010
CVE-2021-27796
A vulnerability in Brocade Fabric OS versions before Brocade Fabric OS v8.0.1b, v7.4.1d could allow an authenticated attacker within the restricted shell environment (rbash) as either the “user” or “factory” account, to read the contents of any file on the filesystem utilizing one of a few available binaries.
Published 2022-02-21 · Modified
6.8EPSS 0.009
CVE-2023-31426
scp, sftp, ftp servers passwords in supportsave
Published 2023-08-01 · Modified
6.8EPSS 0.007
CVE-2025-4663
Denial-of-Service (DoS) after Unusual or Exceptional Conditions vulnerability
Published 2025-07-08 · Analyzed
6.8EPSS 0.003
CVE-2020-15375
Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g contain an improper input validation weakness in the command line interface when secccrypptocfg is invoked. The vulnerability could allow a local authenticated user to run arbitrary commands and perform escalation of privileges.
Published 2020-12-11 · Modified
6.7EPSS 0.003
CVE-2020-13645
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications that fail to provide the server identity, including Balsa before 2.5.11 and 2.6.x before 2.6.1, accept a TLS certificate if the certificate is valid for any host.
Published 2020-05-28 · Modified
6.5EPSS 0.020
CVE-2020-15370
Brocade Fabric OS versions before Brocade Fabric OS v7.4.2g could allow an authenticated, remote attacker to view a user password in cleartext. The vulnerability is due to incorrectly logging the user password in log files.
Published 2020-09-25 · Modified
6.5EPSS 0.010
CVE-2021-27789
The Web application of Brocade Fabric OS before versions Brocade Fabric OS v9.0.1a and v8.2.3a contains debug statements that expose sensitive information to the program's standard output device. An attacker who has compromised the FOS system may utilize this weakness to capture sensitive information, such as user credentials.
Published 2022-03-18 · Modified
6.5EPSS 0.008
CVE-2020-15388
A vulnerability in the Brocade Fabric OS before Brocade Fabric OS v9.0.1a, v8.2.3, v8.2.0_CBN4, and v7.4.2h could allow an authenticated CLI user to abuse the history command to write arbitrary content to files.
Published 2022-03-18 · Modified
6.5EPSS 0.007
CVE-2017-6227
A vulnerability in the IPv6 stack on Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) versions before 7.4.2b, 8.1.2 and 8.2.0 could allow an attacker to cause a denial of service (CPU consumption and device hang) condition by sending crafted Router Advertisement (RA) messages to a targeted system.
Published 2018-02-08 · Modified
6.5EPSS 0.005
CVE-2022-28170
Brocade Fabric OS Web Application services before Brocade Fabric v9.1.0, v9.0.1e, v8.2.3c, v7.4.2j store server and user passwords in the debug statements. This could allow a local user to extract the passwords from a debug file.
Published 2022-10-25 · Modified
6.5EPSS 0.002
CVE-2024-24795
Apache HTTP Server: HTTP Response Splitting in multiple modules
Published 2024-04-04 · Analyzed
6.3EPSS 0.029
CVE-2017-6225
Cross-site scripting (XSS) vulnerability in the web-based management interface of Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) versions before 7.4.2b, 8.1.2 and 8.2.0 could allow remote attackers to execute arbitrary code or access sensitive browser-based information.
Published 2018-02-08 · Modified
6.1EPSS 0.014
CVE-2018-6449
Host Header Injection vulnerability in the http management interface in Brocade Fabric OS versions before v9.0.0 could allow a remote attacker to exploit this vulnerability by injecting arbitrary HTTP headers
Published 2020-09-25 · Modified
6.1EPSS 0.008
CVE-2025-58379
Password Exposure in Brocade Fabric OS
Published 2026-02-03 · Analyzed
6.0EPSS 0.002
CVE-2024-29954
password management API prints sensitive information in log files
Published 2024-06-25 · Modified
5.9EPSS 0.001
CVE-2021-27791
The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading memory addresses outside the intended range. An unauthenticated attacker could discover a request, which could bypass the authentication process.
Published 2021-08-12 · Modified
5.5EPSS 0.006
CVE-2018-6433
A vulnerability in the secryptocfg export command of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to bypass the export file access restrictions and initiate a file copy from the source to a remote system.
Published 2018-11-08 · Modified
5.5EPSS 0.003
CVE-2020-15372
A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2.2a1, 8.2.2c, v7.4.2g, v8.2.0_CBN3, v8.2.1e, v8.1.2k, v9.0.0, could allow a local authenticated attacker to modify shell variables, which may lead to an escalation of privileges or bypassing the logging.
Published 2020-09-25 · Modified
5.5EPSS 0.003
CVE-2021-27798
privileged directory transversal.in Brocade Fabric OS versions 7.4.1.x and 7.3.x
Published 2022-08-05 · Modified
5.5EPSS 0.002
CVE-2022-33181
An information disclosure vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a local authenticated attacker to read sensitive files using switch commands “configshow” and “supportlink”.
Published 2022-10-25 · Modified
5.5EPSS 0.002
CVE-2022-33180
A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5 could allow a local authenticated attacker to export out sensitive files with “seccryptocfg”, “configupload”.
Published 2022-10-25 · Modified
5.5EPSS 0.002
CVE-2023-31429
Multiple commands print sensitive information in the terminal
Published 2023-08-01 · Modified
5.5EPSS 0.002
← Prev2 / 3Next →