Database/Control plane, storage & DevOps
Brocade Fabric OS (unauthenticated remote code execution): Unauthenticated remote code execution on a Fibre Channel
Impact
Unauthenticated remote code execution on a Fibre Channel switch running Fabric OS. Code execution on a SAN switch is total control of the storage fabric: zoning, LUN masking enforcement, and the path every host takes to its data. Affects v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j and earlier.
Who can reach it
Unauthenticated, remote to the switch's management services.
What to do
Fabric OS upgrade plus switch reboot, one fabric at a time so multipathing keeps hosts online. Restrict FOS management reachability to a dedicated OOB network as an immediate config control.
References
Related entries
- Fortinet FortiOS/FortiProxy: Auth bypass via an alternate pathCVE-2022-40684 · Fortinet FortiOS/FortiProxyCritical
- Fortinet FortiOS: SSL-VPN heap-based buffer overflowCVE-2022-42475 · Fortinet FortiOSCritical
- Linux NFS server (nfsd, nfssvc_decode_writeargs): The NFSv2/v3 write argument decoder has no lower bound on the lengthCVE-2022-49280 · Linux NFS server (nfsd, nfssvc_decode_writeargs)Critical
- AMD SMM Supervisor (AMD-SB-7011): The highest-scored AMD platform CVE in this database at 9.8 critical. A flaw in theCVE-2023-20596 · AMD SMM Supervisor (AMD-SB-7011)Critical
- Fortinet FortiOS / FortiProxy SSL-VPN: A heap-based buffer overflow in the SSL-VPN daemon lets a remoteCVE-2023-27997 · Fortinet FortiOS / FortiProxy SSL-VPNCritical
- Progress MOVEit Transfer: Unauthenticated SQL injection into the web appCVE-2023-34362 · Progress MOVEit TransferCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.