Brocade Communications Systems manufactures a portfolio of storage networking, switching, and virtualization products spanning Fabric Operating System firmware, network management tools, and virtual routing appliances like the Vyatta 5400, serving enterprises with mission-critical infrastructure. Vulnerabilities affecting the vendor cluster around input handling and configuration management, with recurring classes including improper input validation, path traversal, OS command injection, and insufficiently protected credentials—patterns consistent with command-line interfaces and firmware-based systems. A meaningful share of the vendor's disclosures reach serious severity, and a moderate tendency exists toward public exploit availability, reflecting the operational value of compromised network infrastructure. Defenders should prioritize patching of internet-exposed or boundary-adjacent instances, particularly virtual routing and management appliances; current exploitation status and severity distribution are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Brocade Communications Systems LLC, a Broadcom Company over time
Of all the CVEs published by Brocade Communications Systems LLC, a Broadcom Company as a CNA, 8.0% affect products that Brocade Communications Systems LLC, a Broadcom Company develops as a vendor.
Of all the CVEs published that affect products developed by Brocade Communications Systems LLC, a Broadcom Company, 46.7% are self-published by Brocade Communications Systems LLC, a Broadcom Company as a CNA.
Signals from CVEs in this vendor scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22555HIGH A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory | Jul 7, 2021 | 7.8 | 96 | YES | YES |
CVE-2018-6443HIGH A vulnerability in Brocade Network Advisor Versions before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected sys | Jan 22, 2019 | 8.1 | 39 | NO | YES |
CVE-2022-33186CRITICAL A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric O | Dec 8, 2022 | 9.8 | 31 | NO | NO |
CVE-2018-6444CRITICAL A Vulnerability in Brocade Network Advisor versions before 14.1.0 could allow a remote unauthenticated attacker to execute arbitray code. The vulnerability could also be exploited | Jan 22, 2019 | 9.8 | 31 | NO | NO |
CVE-2016-8207HIGH A Directory Traversal vulnerability in CliMonitorReportServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to read a | Jan 14, 2017 | 7.5 | 31 | NO | NO |
CVE-2016-8206HIGH A Directory Traversal vulnerability in servlet SoftwareImageUpload in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to wr | Jan 14, 2017 | 7.5 | 31 | NO | NO |
CVE-2016-8205CRITICAL A Directory Traversal vulnerability in DashboardFileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to up | Jan 14, 2017 | 9.8 | 31 | NO | NO |
CVE-2022-22576HIGH An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that th | May 26, 2022 | 8.1 | 28 | NO | NO |
CVE-2014-4868HIGH The management console on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows remote authenticated users to execute arbitrary Linux commands via shell metacharacters | Oct 7, 2014 | 9.0 | 27 | NO | NO |
CVE-2022-27775HIGH An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it | Jun 2, 2022 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (30 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Brocade Communications Systems LLC, a Broadcom Company.
Media articles that mention a CVE ID that affects a product developed by Brocade Communications Systems LLC, a Broadcom Company — matched by CVE ID, not by vendor name.