📦 Fabric Operating System

by Broadcom

🔍 What is Fabric Operating System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-3596

CRITICAL CVSS 9.0 Jul 9, 2024

CVE-2024-3596 allows a local attacker to forge RADIUS protocol responses by exploiting MD5 collisions, enabling them to modify authentication outcomes. This affects any system using RADIUS under RFC 2...

CVE-2022-33186

CRITICAL CVSS 9.8 Dec 8, 2022

This critical vulnerability in Brocade Fabric OS allows remote unauthenticated attackers to execute arbitrary commands on affected switches. Attackers can modify zoning, disable switches/ports, and ch...

CVE-2025-9711

HIGH CVSS 7.8 Feb 3, 2026

This vulnerability allows local authenticated users on Brocade Fabric OS systems to escalate their privileges to root level using specific commands. It affects Brocade SAN switch administrators and op...

CVE-2026-0383

HIGH CVSS 7.8 Feb 3, 2026

This vulnerability in Brocade Fabric OS allows authenticated local attackers with Bash shell access to read insecurely stored file contents, including command history. This affects Brocade SAN switch ...

CVE-2025-58382

HIGH CVSS 7.2 Feb 3, 2026

This vulnerability in Brocade Fabric OS allows authenticated remote attackers with administrative credentials to execute arbitrary commands as root using specific commands. It affects Brocade SAN swit...

CVE-2025-58383

HIGH CVSS 7.2 Feb 3, 2026

This vulnerability allows administrator-level users on Brocade Fabric OS to execute the bind command, enabling privilege escalation and bypassing security controls to run arbitrary commands. It affect...

CVE-2024-7517

HIGH CVSS 7.8 Nov 21, 2024

A command injection vulnerability in Brocade Fabric OS allows local authenticated attackers to escalate privileges via crafted portcfg commands. This affects IP extension platforms including Brocade 7...

CVE-2024-7516

HIGH CVSS 7.1 Nov 12, 2024

This vulnerability allows man-in-the-middle attackers to forge SSH keys during remote operations, enabling them to hijack service sessions on Brocade Fabric OS switches. Attackers could potentially ga...

CVE-2024-5460

HIGH CVSS 8.1 Jun 26, 2024

A vulnerability in Brocade Fabric OS allows authenticated remote attackers to read device data via SNMP using hard-coded default community strings. This affects Brocade Fabric OS versions before v9.0....

CVE-2023-38709

HIGH CVSS 7.3 Apr 4, 2024

CVE-2023-38709 is an input validation vulnerability in Apache HTTP Server that allows malicious backend applications or content generators to split HTTP responses, potentially enabling response smuggl...

CVE-2023-3454

HIGH CVSS 8.6 Apr 4, 2024

This CVE describes a remote code execution vulnerability in Brocade Fabric OS that allows attackers to execute arbitrary code and gain root access to Brocade switches. It affects Brocade Fabric OS ver...

CVE-2023-3489

HIGH CVSS 8.6 Aug 31, 2023

This vulnerability exposes FTP/SFTP/SCP server passwords in clear text within SupportSave files when downgrading from Brocade Fabric OS v9.2.0 to earlier versions. Anyone performing such downgrades on...

CVE-2023-31427

HIGH CVSS 7.8 Aug 1, 2023

This vulnerability allows authenticated local users on Brocade Fabric OS to execute arbitrary commands regardless of their assigned privileges by exploiting improper path validation. Affected systems ...

CVE-2021-27792

HIGH CVSS 7.8 Aug 12, 2021

This vulnerability in Brocade Fabric OS web management interface allows authenticated attackers to crash the HTTP application handler by sending malformed input, requiring a system reboot to restore s...

CVE-2021-27794

HIGH CVSS 7.8 Aug 12, 2021

This authentication bypass vulnerability in Brocade Fabric OS allows attackers to log in with empty or invalid passwords via telnet, SSH, and REST interfaces. It affects Brocade SAN switches running v...

CVE-2020-15387

HIGH CVSS 7.4 Jun 9, 2021

This vulnerability affects Brocade Fabric OS and SANnav systems using SSH host keys shorter than 2048 bits, making SSH communications vulnerable to man-in-the-middle attacks. Attackers could intercept...

CVE-2025-58379

MEDIUM CVSS 5.5 Feb 3, 2026

This vulnerability in Brocade Fabric OS allows local authenticated users with lower privileges to view command line passwords and access sensitive information that should be restricted to higher-privi...

CVE-2025-1976

MEDIUM CVSS 6.7 Apr 24, 2025

This vulnerability allows local admin users on Brocade Fabric OS to escalate privileges to root level, enabling arbitrary code execution. It affects Fabric OS versions 9.1.0 through 9.1.1d6 where root...

CVE-2024-29953

MEDIUM CVSS 4.3 Jun 26, 2024

This vulnerability in Brocade Fabric OS web interface exposes encoded session passwords in session storage on Virtual Fabric platforms. It allows authenticated users to view other users' session passw...

CVE-2023-4162

MEDIUM CVSS 4.4 Aug 31, 2023

This vulnerability allows authenticated privileged users on Brocade Fabric OS switches to cause a segmentation fault (crash) by executing a specific CLI command. It affects Brocade Fabric OS versions ...

CVE-2025-58381

LOW CVSS 2.3 Feb 3, 2026

This vulnerability in Brocade Fabric OS allows authenticated administrators to abuse shell commands (source, ping6, sleep, disown, wait) to manipulate path variables and perform directory traversal at...

CVE-2025-58380

LOW CVSS 2.3 Feb 3, 2026

This vulnerability allows authenticated administrators on Brocade Fabric OS to use the 'grep' shell command for directory traversal, potentially accessing or modifying files outside intended directori...

CVE-2025-4661

LOW CVSS 2.3 Jun 19, 2025

A path traversal vulnerability in Brocade Fabric OS allows local admin users to access files outside intended directories, potentially exposing sensitive information. This affects organizations using ...