CVE-2023-31427
Last modified
CVE-2023-31427 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c, and v9.2.0 Could allow an authenticated, local user with knowledge of full path names inside Brocade Fabric OS to execute any command regardless of assigned privilege. Starting with Fabric OS v9.1.0, “root” account access is disabled.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c, and v9.2.0 Could allow an authenticated, local user with knowledge of full path names inside Brocade Fabric OS to execute any command regardless of assigned privilege. Starting with Fabric OS v9.1.0, “root” account access is disabled.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Fabric Operating System | < 9.1.1c |
References
- https://security.netapp.com/advisory/ntap-20230908-0007/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230908-0007/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-31427?
How severe is CVE-2023-31427?
How do I fix CVE-2023-31427?
Are you affected by CVE-2023-31427?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
