Privilege Escalation Vulnerability in Brocade Fabric OS CLI
CVE-2022-33182
7.8HIGH
Summary
A privilege escalation vulnerability exists in Brocade Fabric OS CLI that affects earlier versions of the software. This vulnerability can be exploited by a local authenticated user executing specific switch commands, such as 'supportlink', 'firmwaredownload', 'portcfgupload', 'license', and 'fosexec'. By leveraging this vulnerability, an attacker could gain root privileges, potentially leading to unauthorized access and control over the affected systems.
Affected Version(s)
Brocade Fabric OS Brocade Fabric OS versions before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved