Vulnerability Intelligence Report
Privilege escalation in Brocade Fabric OS before 9.2.1c3, and 9.2.2 though 9.2.2b
CVE-2025-9711
A vulnerability in Brocade Fabric OS before 9.2.1c3 could allow elevating the privileges of the local authenticated user to “root” using the export option of seccertmgmt and seccryptocfg commands.
No Active Exploit Signals
CVSS Base Score
8.5
HIGH
EPSS Probability:0.13%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-272 ↗CWE-272: Least Privilege Violation
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Brocade | Fabric OS | before 9.2.1c3, and 9.2.2 though 9.2.2b (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.126%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Brocade Communications Systems LLC, a Broadcom Company · Vendor · USA |
| Reserved | 2025-08-29T21:05:15 |
| Published | 2026-02-03T05:19:25 |
| Last Updated | 2026-02-26T15:04:29 |
Community Chatter & Buzz