Vulnerability Intelligence Report
Privileged escalation via crafted use of portcfg command
CVE-2024-7517
A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This specific exploitation is only possible on IP Extension platforms: Brocade 7810, Brocade 7840, Brocade 7850 and on Brocade X6 or X7 directors with an SX-6 Extension blade installed. The attacker must be logged into the switch via SSH or serial console to conduct the attack.
No Active Exploit Signals
CVSS Base Score
8.5
HIGH
EPSS Probability:0.63%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-78 ↗CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Brocade | Fabric OS | Brocade Fabric OS versions before 9.2.0c, and 9.2.1 through 9.2.1a (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.626%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Brocade Communications Systems LLC, a Broadcom Company · Vendor · USA |
| Reserved | 2024-08-05T22:49:54 |
| Published | 2024-11-21T05:53:34 |
| Last Updated | 2025-09-09T19:02:20 |
Community Chatter & Buzz