CVE-2023-4162
Last modified
CVE-2023-4162 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. A segmentation fault can occur in Brocade Fabric OS after Brocade Fabric OS v9.0 and before Brocade Fabric OS v9.2.0a through the passwdcfg command. This could allow an authenticated privileged user local user to crash a Brocade Fabric OS swith using the cli “passwdcfg --set -expire -minDiff“.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
A segmentation fault can occur in Brocade Fabric OS after Brocade Fabric OS v9.0 and before Brocade Fabric OS v9.2.0a through the passwdcfg command. This could allow an authenticated privileged user local user to crash a Brocade Fabric OS swith using the cli “passwdcfg --set -expire -minDiff“.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Fabric Operating System | >= 9.0.1a, < 9.2.0a |
References
- https://security.netapp.com/advisory/ntap-20231124-0010/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20231124-0010/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-4162?
How severe is CVE-2023-4162?
How do I fix CVE-2023-4162?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-41613EzViz Studio v2.2.0 is vulnerable to DLL hijacking.7.8
- CVE-2023-41614A stored cross-site scripting (XSS) vulnerability in the Add…4.8
- CVE-2023-41615Zoo Management System v1.0 was discovered to contain multipl…9.8
- CVE-2023-41616A reflected cross-site scripting (XSS) vulnerability in the …4.8
- CVE-2023-41618Emlog Pro v2.1.14 was discovered to contain a reflective cro…6.1
- CVE-2023-41619Emlog Pro v2.1.14 was discovered to contain a cross-site scr…6.1
- CVE-2023-41621A Cross Site Scripting (XSS) vulnerability was discovered in…6.1
- CVE-2023-41623Emlog version pro2.1.14 was discovered to contain a SQL inje…7.2
- CVE-2023-41626Gradio v3.27.0 was discovered to contain an arbitrary file u…4.8
- CVE-2023-41627O-RAN Software Community ric-plt-lib-rmr v4.9.0 does not val…7.5
- CVE-2023-41628An issue in O-RAN Software Community E2 G-Release allows att…7.5
- CVE-2023-41629A lack of input sanitizing in the file download feature of e…7.5
Are you affected by CVE-2023-4162?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
