CVE-2024-7517
HIGHBrocade Fabric OS < 9.2.0c and 9.2.1-9.2.1a - Authenticated Command Injection via portcfg
Title source: llmDescription
A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This specific exploitation is only possible on IP Extension platforms: Brocade 7810, Brocade 7840, Brocade 7850 and on Brocade X6 or X7 directors with an SX-6 Extension blade installed. The attacker must be logged into the switch via SSH or serial console to conduct the attack.
References (1)
Core 1
Core References
Scores
CVSS v3
7.8
EPSS
0.0012
EPSS Percentile
31.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (2)
broadcom/fabric_operating_system
< 9.2.0c
brocade/fabric_operating_system
< 9.2.0c
Published
Nov 21, 2024
Tracked Since
Feb 18, 2026