GPU VulnDB

Database/Control plane, storage & DevOps

Brocade Fabric OS (unauthenticated remote code execution): Unauthenticated remote code execution on a Fibre Channel

CVE-2022-33186Control plane, storage & DevOpscurated

Impact

Unauthenticated remote code execution on a Fibre Channel switch running Fabric OS. Code execution on a SAN switch is total control of the storage fabric: zoning, LUN masking enforcement, and the path every host takes to its data. Affects v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j and earlier.

Who can reach it

Unauthenticated, remote to the switch's management services.

What to do

Fabric OS upgrade plus switch reboot, one fabric at a time so multipathing keeps hosts online. Restrict FOS management reachability to a dedicated OOB network as an immediate config control.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.