Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c, and v9.2.0 Could allow an authenticated, local user with knowledge of full path names inside Brocade Fabric OS to execute any command regardless of assigned privilege. Starting with Fabric OS v9.1.0, “root” account access is disabled.
References
Link | Resource |
---|---|
https://security.netapp.com/advisory/ntap-20230908-0007/ | Third Party Advisory |
https://support.broadcom.com/external/content/SecurityAdvisories/0/22379 | Vendor Advisory |
Configurations
History
16 Feb 2024, 17:35
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://security.netapp.com/advisory/ntap-20230908-0007/ - Third Party Advisory |
08 Sep 2023, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
07 Aug 2023, 20:14
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:* | |
CWE | CWE-22 | |
First Time |
Broadcom
Broadcom fabric Operating System |
|
References | (MISC) https://support.broadcom.com/external/content/SecurityAdvisories/0/22379 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
01 Aug 2023, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-01 23:15
Updated : 2024-02-28 20:33
NVD link : CVE-2023-31427
Mitre link : CVE-2023-31427
CVE.ORG link : CVE-2023-31427
JSON object : View
Products Affected
broadcom
- fabric_operating_system
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')