CVE-2022-28169

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
25/10/2022
Last modified:
09/05/2025

Description

Brocade Webtools in Brocade Fabric OS versions before Brocade Fabric OS versions v9.1.1, v9.0.1e, and v8.2.3c could allow a low privilege webtools, user, to gain elevated admin rights, or privileges, beyond what is intended or entitled for that user. By exploiting this vulnerability, a user whose role is not an admin can create a new user with an admin role using the operator session id. The issue was replicated after intercepting the admin, and operator authorization headers sent unencrypted and editing a user addition request to use the operator's authorization header.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:* 8.0.0 (including) 8.2.3c (excluding)
cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:* 9.0.0 (including) 9.0.1e (excluding)
cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:* 9.1.0 (including) 9.1.1 (excluding)