VendorsBroadcomfabric_operating_systemall versions
Vulnerabilities

Broadcom Fabric Operating System (FOS)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

95CVEs
CVE-2018-6447
A Reflective XSS Vulnerability in HTTP Management Interface in Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g could allow authenticated attackers with access to the web interface to hijack a user’s session and take over the account.
Published 2020-09-25 · Modified
5.4EPSS 0.005
CVE-2021-22876
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.
Published 2021-04-01 · Modified
5.3EPSS 0.053
CVE-2020-15386
Brocade Fabric OS prior to v9.0.1a and 8.2.3a and after v9.0.0 and 8.2.2d may observe high CPU load during security scanning, which could lead to a slower response to CLI commands and other operations.
Published 2021-06-09 · Modified
5.3EPSS 0.010
CVE-2021-27793
ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fabric OS before Brocade Fabric OS v8.2.3a and after v8.2.0 could cause a user with a valid account to be unable to log into the switch.
Published 2021-08-12 · Modified
5.3EPSS 0.009
CVE-2004-1663
Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets.
Published 2005-02-20 · Modified
5.0EPSS 0.042
CVE-2025-4661
Path transversal vulnerability potentially leading to sensitive information disclosure
Published 2025-06-19 · Analyzed
4.8EPSS 0.002
CVE-2025-58380
Directory transversal vulnerability in Brocade Fabric OS before 9.2.1 using grep command
Published 2026-02-03 · Analyzed
4.6EPSS 0.002
CVE-2025-58381
Directory transversal vulnerability in Brocade Fabric OS before 9.2.1c2 and 9.2.2 through 9.2.2a using various shell commands
Published 2026-02-03 · Analyzed
4.6EPSS 0.002
CVE-2020-29660
A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24.
Published 2020-12-09 · Modified
4.4EPSS 0.005
CVE-2023-4163
Possible buffer overflow in portcfgfportbuffers in Brocade Fabric OS
Published 2023-08-31 · Modified
4.4EPSS 0.003
CVE-2023-4162
Segmentation fault in Brocade Fabric OS after Brocade Fabric OS v9.0
Published 2023-08-31 · Analyzed
4.4EPSS 0.002
CVE-2021-22890
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server and then wrongly "short-cut" the host handshake. When confusing the tickets, a HTTPS proxy can trick libcurl to use the wrong session ticket resume for the host and thereby circumvent the server TLS certificate check and make a MITM attack to be possible to perform unnoticed. Note that such a malicious HTTPS proxy needs to provide a certificate that curl will accept for the MITMed server for an attack to work - unless curl has been told to ignore the server certificate check.
Published 2021-04-01 · Modified
4.3EPSS 0.031
CVE-2020-15376
Brocade Fabric OS versions before v9.0.0 and after version v8.1.0, configured in Virtual Fabric mode contain a weakness in the ldap implementation that could allow a remote ldap user to login in the Brocade Fibre Channel SAN switch with "user" privileges if it is not associated with any groups.
Published 2020-12-11 · Modified
4.3EPSS 0.009
CVE-2024-29953
Encoded session passwords on session storage for Virtual Fabric platforms
Published 2024-06-25 · Analyzed
4.3EPSS 0.003
CVE-2023-5973
Truncated port name
Published 2024-04-05 · Modified
4.3EPSS 0.002
← Prev3 / 3