Vulnerability Intelligence Report
Privilege escalation in Brocade Fabric before 9.2.1c2 and 9.2.2 through 9.2.2a
CVE-2025-58382
A vulnerability in the secure configuration of authentication and management services in Brocade Fabric OS before Fabric OS 9.2.1c2 could allow an authenticated, remote attacker with administrative credentials to execute arbitrary commands as root using “supportsave”, “seccertmgmt”, “configupload” command.
No Active Exploit Signals
CVSS Base Score
8.5
HIGH
EPSS Probability:0.60%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-305 ↗CWE-305: Authentication Bypass by Primary Weakness
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Brocade | Fabric OS | before 9.2.1c2 and 9.2.2 through 9.2.2a (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.602%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Brocade Communications Systems LLC, a Broadcom Company · Vendor · USA |
| Reserved | 2025-08-29T21:03:16 |
| Published | 2026-02-03T01:39:55 |
| Last Updated | 2026-02-26T15:04:30 |
Community Chatter & Buzz