Executive brief
Broadcom Brocade Fabric OS contains a code injection vulnerability (CWE-94/CWE-78) that allows a local user with administrative privileges to execute arbitrary code with full root privileges. This vulnerability affects versions 9.1.0 through 9.1.1d6, where root access was intended to be restricted.
Affected products
- Broadcom Fabric OS 9.1.0 through 9.1.1d6
Timeline
- 2025-04-23: disclosed: Initial CVE entry received from Brocade Communications Systems, LLC
- 2025-04-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-04-28: exploited: Reported as exploited in the wild per CISA KEV entry