Vulnerability Description
A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS v9.1.1 could allow a local authenticated user to perform privilege escalation to root by breaking the rbash shell. Starting with Fabric OS v9.1.0, “root” account access is disabled.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Fabric Operating System | 9.1.0 |
Related Weaknesses (CWE)
References
- https://security.netapp.com/advisory/ntap-20230908-0007/Third Party Advisory
- https://support.broadcom.com/external/content/SecurityAdvisories/0/22407Vendor Advisory
- https://security.netapp.com/advisory/ntap-20230908-0007/Third Party Advisory
- https://support.broadcom.com/external/content/SecurityAdvisories/0/22407Vendor Advisory
FAQ
What is CVE-2023-31425?
CVE-2023-31425 is a vulnerability with a CVSS score of 7.8 (HIGH). A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS v9.1.1 could allow a local authenticated user to perform privilege escalation t...
How severe is CVE-2023-31425?
CVE-2023-31425 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-31425?
Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Fabric Operating System.