Brocade Fabric OS flaw could allow code injection attacks

A high severity flaw affecting Broadcom’s Brocade Fabric OS (FOS) has allowed attackers to run arbitrary code on affected environments with full root-level privileges.

The flaw, tracked as CVE-2025-1976, is particularly dangerous as it can allow complete takeover of FOS devices, including Fibre switches and directors, which are core to Storage Area Networks (SANs), potentially enabling attackers to modify system files, configuration data, firmware, security mechanisms, and install persistent malware.

“Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privilege on Fabric OS versions 9.1.0 through 9.1.1d6,” reads a Broadcom description.

Broadcom has issued a fix through the Brocade FOS 9.1.1d7 update.



Source link

Leave a Comment