CVE-2023-31427

Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c, and v9.2.0 Could allow an authenticated, local user with knowledge of full path names inside Brocade Fabric OS to execute any command regardless of assigned privilege. Starting with Fabric OS v9.1.0, “root” account access is disabled.
Configurations

Configuration 1 (hide)

cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:*

History

16 Feb 2024, 17:35

Type Values Removed Values Added
References () https://security.netapp.com/advisory/ntap-20230908-0007/ - () https://security.netapp.com/advisory/ntap-20230908-0007/ - Third Party Advisory

08 Sep 2023, 17:15

Type Values Removed Values Added
References
  • (MISC) https://security.netapp.com/advisory/ntap-20230908-0007/ -

07 Aug 2023, 20:14

Type Values Removed Values Added
CWE CWE-22
First Time Broadcom
Broadcom fabric Operating System
CPE cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References (MISC) https://support.broadcom.com/external/content/SecurityAdvisories/0/22379 - (MISC) https://support.broadcom.com/external/content/SecurityAdvisories/0/22379 - Vendor Advisory

01 Aug 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-01 23:15

Updated : 2024-02-16 17:35


NVD link : CVE-2023-31427

Mitre link : CVE-2023-31427

CVE.ORG link : CVE-2023-31427


JSON object : View

Products Affected

broadcom

  • fabric_operating_system
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')