Webtools Vulnerability in Brocade Fabric OS
CVE-2022-28169
8.8HIGH
Summary
A vulnerability in Brocade Webtools of Brocade Fabric OS allows a user with low privileges to escalate their privileges and gain admin rights. This flaw occurs when authorization headers, specifically the operator's session ID, are transmitted without encryption, making it susceptible to interception. Malicious users can exploit this weakness to create new admin-user roles, compromising the security and integrity of the system. Users on older versions of Brocade Fabric OS should prioritize updating to mitigate this risk.
Affected Version(s)
Brocade Fabric OS Brocade Fabric OS versions before Brocade Fabric OS versions v9.1.1, v9.0.1e, and v8.2.3c
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved