Command Injection Vulnerability in Brocade 6547 Embedded Switch Blade
CVE-2024-5461
8.6HIGH
What is CVE-2024-5461?
A command injection vulnerability exists within the Simple Network Management Protocol (SNMP) implementation on the Brocade 6547 (FC5022) embedded switch blade. This issue arises from the internal script execution that occurs when SNMP operations are performed. An attacker with authentication can exploit this vulnerability to inject arbitrary commands into the SNMP binary, enabling them to execute unauthorized commands with root privileges. Organizations using the Brocade 6547 (FC5022) should review their SNMP configurations and apply necessary security measures to mitigate potential exploitation.
Affected Version(s)
Brocade Fabric OS Brocade 6547 (FC5022) embedded switch blade before 8.2.3e1_pha
References
CVSS V4
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved