Privilege Escalation Vulnerability in Brocade Fabric OS CLI
CVE-2022-33182

7.8HIGH

Key Information:

Vendor
Broadcom
Vendor
CVE Published:
25 October 2022

Summary

A privilege escalation vulnerability exists in Brocade Fabric OS CLI that affects earlier versions of the software. This vulnerability can be exploited by a local authenticated user executing specific switch commands, such as 'supportlink', 'firmwaredownload', 'portcfgupload', 'license', and 'fosexec'. By leveraging this vulnerability, an attacker could gain root privileges, potentially leading to unauthorized access and control over the affected systems.

Affected Version(s)

Brocade Fabric OS Brocade Fabric OS versions before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.