Fabric Operating System
Vendor:
First CVE: Sep 4, 2004 · Active for 21 years
95
Total CVEs
More Total CVEs than 99% of tracked products
7.9
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
1.1%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Fabric Operating System over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 4, 2004
21 years ago
Most Recent CVE
Feb 3, 2026
172 days ago
CVE Severity & Scoring
Fabric Operating System95 CVEs
38%
48%
9%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local37 (38.9%)
Network53 (55.8%)
Unknown1 (1.1%)
Physical0 (0.0%)
Adjacent Network4 (4.2%)
Attack Complexity
Low87 (91.6%)
High7 (7.4%)
Unknown1 (1.1%)
User Interaction
None87 (91.6%)
Unknown1 (1.1%)
Required7 (7.4%)
Privileges Required
Low47 (49.5%)
High12 (12.6%)
None35 (36.8%)
Unknown1 (1.1%)
Top CVEs
Signals from CVEs in this product scope (95 CVEs).
95 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1976MEDIUM Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges | Apr 24, 2025 | 6.7 | 62 | YES | NO |
CVE-2020-1967HIGH Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect hand | Apr 21, 2020 | 7.5 | 51 | NO | NO |
CVE-2024-3596CRITICAL RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any ot | Jul 9, 2024 | 9.0 | 38 | NO | NO |
CVE-2022-33186CRITICAL A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric O | Dec 8, 2022 | 9.8 | 31 | NO | NO |
CVE-2019-18805CRITICAL An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when usersp | Nov 7, 2019 | 9.8 | 31 | NO | NO |
CVE-2023-3454CRITICAL Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use this to gain root access to th | Apr 4, 2024 | 9.8 | 30 | NO | NO |
CVE-2021-27797CRITICAL Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow atta | Feb 21, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-15778HIGH scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedl | Jul 24, 2020 | 7.4 | 30 | NO | NO |
CVE-2020-15374CRITICAL Rest API in Brocade Fabric OS v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c is vulnerable to multiple instances of reflected input. | Sep 25, 2020 | 9.8 | 29 | NO | NO |
CVE-2022-33183HIGH A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a remote authenticated attacker to perform stack buffer ove | Oct 25, 2022 | 8.8 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (95 CVEs).
CISA KEV
1 CVE
1.1% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (95 CVEs).
Media Mentions
Signals from CVEs in this product scope (95 CVEs).
Top CNAs Publishing CVEs For Fabric Operating System
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.2.2 | 1 | 4.9 | 0.3% | 0 | 0 |
| 9.2.0 | 1 | 7.5 | 0.3% | 0 | 0 |
| 9.1.0 | 5 | 6.8 | 0.2% | 0 | 0 |
| 9.0.1e | 1 | 9.8 | 1.6% | 0 | 0 |
| 9.0.1a | 1 | 5.3 | 0.9% | 0 | 0 |
| 9.0.1 | 2 | 5.3 | 0.9% | 0 | 0 |
| 9.0.0b | 1 | 5.3 | 1.0% | 0 | 0 |
| 9.0.0a | 1 | 5.3 | 1.0% | 0 | 0 |
| 8.2.3c | 1 | 9.8 | 1.6% | 0 | 0 |
| 8.2.3 | 4 | 5.6 | 0.8% | 0 | 0 |
| 8.2.2c | 3 | 9.0 | 1.5% | 0 | 0 |
| 8.2.2b | 6 | 8.5 | 1.2% | 0 | 0 |
| 8.2.2a1 | 6 | 8.5 | 1.2% | 0 | 0 |
| 8.2.2a | 5 | 8.7 | 1.3% | 0 | 0 |
| 8.2.2 | 5 | 8.7 | 1.3% | 0 | 0 |
| 8.2.1d | 6 | 8.5 | 1.2% | 0 | 0 |
| 8.2.1c | 6 | 8.5 | 1.2% | 0 | 0 |
| 8.2.1b | 7 | 8.4 | 1.1% | 0 | 0 |
| 8.2.1a | 7 | 8.4 | 1.1% | 0 | 0 |
| 8.2.1 | 7 | 8.4 | 1.1% | 0 | 0 |