Brocade Fabric Operating System
Vendor:
First CVE: Apr 2, 2020 · Active for 6 years
11
Total CVEs
More Total CVEs than 90% of tracked products
3.7
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Brocade Fabric Operating System over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 2, 2020
6 years ago
Most Recent CVE
Aug 2, 2023
1,091 days ago
CVE Severity & Scoring
Brocade Fabric Operating System11 CVEs
64%
36%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local7 (63.6%)
Network4 (36.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None8 (72.7%)
Unknown0 (0.0%)
Required3 (27.3%)
Privileges Required
Low6 (54.5%)
High0 (0.0%)
None5 (45.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-1927MEDIUM In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to a | Apr 2, 2020 | 6.1 | 43 | NO | NO |
CVE-2023-31432HIGH Through manipulation of passwords or other variables, using commands such as portcfgupload, configupload, license, myid, a non-privileged user could obtain root privileges in Broca | Aug 2, 2023 | 7.8 | 22 | NO | NO |
CVE-2023-31926HIGH System files could be overwritten using the less command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0. | Aug 2, 2023 | 7.1 | 21 | NO | NO |
CVE-2020-12243HIGH In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash). | Apr 28, 2020 | 7.5 | 21 | NO | NO |
CVE-2020-35507MEDIUM There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed | Jan 4, 2021 | 5.5 | 20 | NO | NO |
CVE-2023-31928MEDIUM A reflected cross-site scripting (XSS) vulnerability exists in Brocade Webtools PortSetting.html of Brocade Fabric OS version before Brocade Fabric OS v9.2.0 that could allow a re | Aug 2, 2023 | 6.1 | 18 | NO | NO |
CVE-2021-23133HIGH A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged p | Apr 22, 2021 | 7.0 | 18 | NO | NO |
CVE-2023-31927MEDIUM An information disclosure in the web interface of Brocade Fabric OS versions before Brocade Fabric OS v9.2.0 and v9.1.1c, could allow a remote unauthenticated attacker to get techn | Aug 2, 2023 | 5.3 | 17 | NO | NO |
CVE-2023-31431MEDIUM A buffer overflow vulnerability in “diagstatus” command in Brocade Fabric OS before Brocade Fabric v9.2.0 and v9.1.1c could allow an authenticated user to crash the Brocade Fabric | Aug 2, 2023 | 5.5 | 17 | NO | NO |
CVE-2023-31430MEDIUM A buffer overflow vulnerability in “secpolicydelete” command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0 could allow an authenticated privileged user to crash | Aug 2, 2023 | 5.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Brocade Fabric Operating System
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.2.0 | 3 | 5.5 | 0.2% | 0 | 0 |