CVE-2024-7517
Severity CVSS v4.0:
HIGH
Type:
CWE-78
OS Command Injections
Publication date:
21/11/2024
Last modified:
20/02/2026
Description
A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command.<br />
<br />
This specific exploitation is only possible on IP Extension platforms: Brocade 7810, Brocade 7840, Brocade 7850 and on Brocade X6 or X7 directors with an SX-6 Extension blade installed. The attacker must be logged into the switch via SSH or serial console to conduct the attack.
Impact
Base Score 4.0
8.50
Severity 4.0
HIGH
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:* | 9.2.0c (including) | |
| cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:* | 9.2.1 (including) | 9.2.1a (including) |
To consult the complete list of CPE names with products and versions, see this page



