Fabric Operating System

Vendor:

First CVE: Sep 4, 2004 · Active for 21 years

95
Total CVEs
More Total CVEs than 99% of tracked products
7.9
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
1.1%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Fabric Operating System over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 4, 2004
21 years ago
Most Recent CVE
Feb 3, 2026
172 days ago

CVE Severity & Scoring

Fabric Operating System95 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local37 (38.9%)
Network53 (55.8%)
Unknown1 (1.1%)
Physical0 (0.0%)
Adjacent Network4 (4.2%)
Attack Complexity
Low87 (91.6%)
High7 (7.4%)
Unknown1 (1.1%)
User Interaction
None87 (91.6%)
Unknown1 (1.1%)
Required7 (7.4%)
Privileges Required
Low47 (49.5%)
High12 (12.6%)
None35 (36.8%)
Unknown1 (1.1%)

Top CVEs

Signals from CVEs in this product scope (95 CVEs).

95 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges
Apr 24, 20256.762YESNO
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect hand
Apr 21, 20207.551NONO
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any ot
Jul 9, 20249.038NONO
A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric O
Dec 8, 20229.831NONO
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when usersp
Nov 7, 20199.831NONO
Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use this to gain root access to th
Apr 4, 20249.830NONO
Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow atta
Feb 21, 20229.830NONO
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedl
Jul 24, 20207.430NONO
Rest API in Brocade Fabric OS v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c is vulnerable to multiple instances of reflected input.
Sep 25, 20209.829NONO
A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a remote authenticated attacker to perform stack buffer ove
Oct 25, 20228.828NONO

Exploit Exposure

Signals from CVEs in this product scope (95 CVEs).

CISA KEV
1 CVE
1.1% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (95 CVEs).

Media Mentions

Signals from CVEs in this product scope (95 CVEs).

Top CNAs Publishing CVEs For Fabric Operating System

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.2.214.90.3%00
9.2.017.50.3%00
9.1.056.80.2%00
9.0.1e19.81.6%00
9.0.1a15.30.9%00
9.0.125.30.9%00
9.0.0b15.31.0%00
9.0.0a15.31.0%00
8.2.3c19.81.6%00
8.2.345.60.8%00
8.2.2c39.01.5%00
8.2.2b68.51.2%00
8.2.2a168.51.2%00
8.2.2a58.71.3%00
8.2.258.71.3%00
8.2.1d68.51.2%00
8.2.1c68.51.2%00
8.2.1b78.41.1%00
8.2.1a78.41.1%00
8.2.178.41.1%00