Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Brocade Communications Systems LLC, a Broadcom Company

First CVE: Sep 4, 2004Active for: 22 yearsTotal CVEs: 30
50.5
VTI Score
TOP TARGET

Brocade Communications Systems manufactures a portfolio of storage networking, switching, and virtualization products spanning Fabric Operating System firmware, network management tools, and virtual routing appliances like the Vyatta 5400, serving enterprises with mission-critical infrastructure. Vulnerabilities affecting the vendor cluster around input handling and configuration management, with recurring classes including improper input validation, path traversal, OS command injection, and insufficiently protected credentials—patterns consistent with command-line interfaces and firmware-based systems. A meaningful share of the vendor's disclosures reach serious severity, and a moderate tendency exists toward public exploit availability, reflecting the operational value of compromised network infrastructure. Defenders should prioritize patching of internet-exposed or boundary-adjacent instances, particularly virtual routing and management appliances; current exploitation status and severity distribution are shown alongside this summary.

FAUCET AI Generated
30
Total CVEs
More Total CVEs than 97% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
3.3%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Brocade Communications Systems LLC, a Broadcom Company over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 4, 2004
21 years ago
Most Recent CVE
Jul 17, 2025
372 days ago

Self-Reporting Analysis

Of all the CVEs published by Brocade Communications Systems LLC, a Broadcom Company as a CNA, 8.0% affect products that Brocade Communications Systems LLC, a Broadcom Company develops as a vendor.

92.0%
Self-reported: 14 (8.0%)
Third-party: 160 (92.0%)

Of all the CVEs published that affect products developed by Brocade Communications Systems LLC, a Broadcom Company, 46.7% are self-published by Brocade Communications Systems LLC, a Broadcom Company as a CNA.

46.7%
53.3%
Self-published: 14 (46.7%)
Other CNAs: 16 (53.3%)

Products(52 total)

Top CVEs

Signals from CVEs in this vendor scope (30 CVEs).

30 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-22555HIGH
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory
Jul 7, 20217.896YESYES
CVE-2018-6443HIGH
A vulnerability in Brocade Network Advisor Versions before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected sys
Jan 22, 20198.139NOYES
CVE-2022-33186CRITICAL
A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric O
Dec 8, 20229.831NONO
CVE-2018-6444CRITICAL
A Vulnerability in Brocade Network Advisor versions before 14.1.0 could allow a remote unauthenticated attacker to execute arbitray code. The vulnerability could also be exploited
Jan 22, 20199.831NONO
CVE-2016-8207HIGH
A Directory Traversal vulnerability in CliMonitorReportServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to read a
Jan 14, 20177.531NONO
CVE-2016-8206HIGH
A Directory Traversal vulnerability in servlet SoftwareImageUpload in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to wr
Jan 14, 20177.531NONO
CVE-2016-8205CRITICAL
A Directory Traversal vulnerability in DashboardFileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to up
Jan 14, 20179.831NONO
CVE-2022-22576HIGH
An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that th
May 26, 20228.128NONO
CVE-2014-4868HIGH
The management console on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows remote authenticated users to execute arbitrary Linux commands via shell metacharacters
Oct 7, 20149.027NONO
CVE-2022-27775HIGH
An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it
Jun 2, 20227.526NONO
View all 30 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products30 CVEs
40%
50%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (20.0%)
Network15 (50.0%)
Unknown8 (26.7%)
Physical0 (0.0%)
Adjacent Network1 (3.3%)
Attack Complexity
Low20 (66.7%)
High2 (6.7%)
Unknown8 (26.7%)
User Interaction
None18 (60.0%)
Unknown8 (26.7%)
Required4 (13.3%)
Privileges Required
Low9 (30.0%)
High0 (0.0%)
None13 (43.3%)
Unknown8 (26.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (30 CVEs).

CISA KEV
1 CVE
3.3% of CVEs· 99th percentile
Metasploit
1 CVE
3.3% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
6.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Brocade Communications Systems LLC, a Broadcom Company.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Brocade Communications Systems LLC, a Broadcom Company — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Brocade Communications Systems LLC, a Broadcom Company's Products

View all 5 CNAs →

Top CWEs