CVE-2023-31427

Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c, and v9.2.0 Could allow an authenticated, local user with knowledge of full path names inside Brocade Fabric OS to execute any command regardless of assigned privilege. Starting with Fabric OS v9.1.0, “root” account access is disabled.
Configurations

Configuration 1 (hide)

cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:*

History

16 Feb 2024, 17:35

Type Values Removed Values Added
References () https://security.netapp.com/advisory/ntap-20230908-0007/ - () https://security.netapp.com/advisory/ntap-20230908-0007/ - Third Party Advisory

07 Aug 2023, 20:14

Type Values Removed Values Added
CPE cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:*
References (MISC) https://support.broadcom.com/external/content/SecurityAdvisories/0/22379 - (MISC) https://support.broadcom.com/external/content/SecurityAdvisories/0/22379 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-22

01 Aug 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-01 23:15

Updated : 2024-02-16 17:35


NVD link : CVE-2023-31427

Mitre link : CVE-2023-31427

CVE.ORG link : CVE-2023-31427


JSON object : View

Products Affected

broadcom

  • fabric_operating_system
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')