MEDIUM

CVE-2025-1976

Broadcom Fabric Operating System 2025-04-24 CVSS v3.1
CVSS
6.7
KEV

Description

Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.

Summary dbcve.org

A local privilege escalation vulnerability exists in Brocade Fabric OS versions 9.1.0 through 9.1.1d6 where the intended removal of root access was incomplete. A local user with admin-level privileges can bypass this restriction and execute arbitrary code with full root privileges.

Mitigation

Upgrade Fabric OS to a version beyond 9.1.1d6 where the incomplete root access removal has been properly remediated.

Weakness (CWE)

CWE-94 Code Injection
CWE-78 OS Command Injection

EPSS Score

0.69%
Probability of exploitation in next 30 days
51.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE