Privilege issues in multiple commands
CVE-2023-31432
7.8HIGH
What is CVE-2023-31432?
A vulnerability exists within Brocade Fabric OS that allows non-privileged users to exploit specific commands such as portcfgupload, configupload, license, and myid. This manipulation can lead to unauthorized escalation of privileges, granting users root access to the system. Affected versions include all prior to Brocade Fabric OS v9.1.1c and v9.2.0, posing a significant security risk for users relying on these versions.
Affected Version(s)
Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved