Vulnerability Description
Through manipulation of passwords or other variables, using commands such as portcfgupload, configupload, license, myid, a non-privileged user could obtain root privileges in Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c and v9.2.0.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Brocade Fabric Operating System | < 9.1.1c |
Related Weaknesses (CWE)
References
- https://security.netapp.com/advisory/ntap-20230908-0007/Third Party Advisory
- https://support.broadcom.com/external/content/SecurityAdvisories/0/22385Vendor Advisory
- https://security.netapp.com/advisory/ntap-20230908-0007/Third Party Advisory
- https://support.broadcom.com/external/content/SecurityAdvisories/0/22385Vendor Advisory
FAQ
What is CVE-2023-31432?
CVE-2023-31432 is a vulnerability with a CVSS score of 7.8 (HIGH). Through manipulation of passwords or other variables, using commands such as portcfgupload, configupload, license, myid, a non-privileged user could obtain root privileges in Brocade Fabric OS version...
How severe is CVE-2023-31432?
CVE-2023-31432 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-31432?
Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Brocade Fabric Operating System.