← Back to CVE List
Vulnerability Intelligence Report
Privileged escalation via crafted use of portcfg command

CVE-2024-7517

A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This specific exploitation is only possible on IP Extension platforms: Brocade 7810, Brocade 7840, Brocade 7850 and on Brocade X6 or X7 directors with an SX-6 Extension blade installed. The attacker must be logged into the switch via SSH or serial console to conduct the attack.

No Active Exploit Signals
CVSS Base Score
8.5
HIGH
EPSS Probability:0.63%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-78 ↗CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Affected Products & Versions

Vendor Product Affected Versions
Brocade Fabric OS Brocade Fabric OS versions before 9.2.0c, and 9.2.1 through 9.2.1a (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.626%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityBrocade Communications Systems LLC, a Broadcom Company · Vendor · USA
Reserved2024-08-05T22:49:54
Published2024-11-21T05:53:34
Last Updated2025-09-09T19:02:20

LINK COPIED TO CLIPBOARD