Brocade
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Brocade product.
RSS Feeds for Brocade security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Brocade products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Brocade Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 23 vulnerabilities in Brocade with an average score of 7.9 out of ten. Last year, in 2025 Brocade had 3 security vulnerabilities published. That is, 20 more vulnerabilities have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 23 | 7.93 |
| 2025 | 3 | 0.00 |
| 2024 | 6 | 6.80 |
| 2023 | 11 | 6.12 |
| 2022 | 14 | 7.14 |
| 2021 | 1 | 8.30 |
| 2020 | 14 | 7.25 |
| 2019 | 3 | 0.00 |
| 2018 | 12 | 7.80 |
It may take a day or so for new Brocade vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Brocade Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-85417 | Sep 25, 2026 |
SNMP Password Logging in Brocade SANnav (CVE-2026-85417)Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions. Individuals with read access to system logs or support bundles can retrieve these credentials, leading to unauthorized read or management access to monitored switch environments |
|
| CVE-2026-14441 | Sep 24, 2026 |
Java Cache Key Handling Comparison Flaw in Brocade ProductA logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when processing specific user account structures. The issue has been remediated by updating the internal comparison routines to ensure accurate object evaluation and prevent potential identity mismatch conditions. |
|
| CVE-2026-14442 | Sep 24, 2026 |
SANnav job scheduler logs cleartext credentialsAn information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be written to application logs in plain text. When scheduled support save jobs or related operational tasks are executed, sensitive parameters including external server passwords and archive protection keys are logged without proper masking. A local or authenticated user with access to application logs or support bundles can view these cleartext credentials, potentially leading to unauthorized access to remote backup targets or protected archives. |
|
| CVE-2026-14443 | Sep 24, 2026 |
Brocade SANnav <3.0.1a Log Sanitization Flaw Exposes IPsec PSKsIncomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system logs. Individuals with read access to container logs or support archives can obtain these keys, leading to the potential compromise of encrypted network tunnels. |
|
| CVE-2026-82372 | Sep 24, 2026 |
Brocade SANnav <3.0.1a Sensitive Data Exposure: PSK LoggedImproper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in application logs. Individuals with read access to system log files or support bundles can view these credentials, leading to the potential exposure of keys used to secure network tunnels. |
|
| CVE-2026-82371 | Sep 24, 2026 |
Brocade SANnav Log File Plaintext Exposure (v<3.0.1a)Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals with file read access to retrieve administrative switch credentials and active session tokens. An attacker with access to system logs or support bundles can leverage exposed authentication details to compromise managed network infrastructure and access active application sessions. This vulnerability affects Brocade SANnav versions before 3.0.1a. |
|
| CVE-2026-82370 | Sep 23, 2026 |
Brocade SANnav Orchestrator RCE before 3.0.1aUnauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service permits network-adjacent attackers to execute arbitrary administrative switch CLI commands and issue container management instructions. This could allow an attacker to alter Fibre Channel fabric switch configurations or manipulate application container runtimes. This vulnerability affects Brocade SANnav versions before 3.0.1a. |
|
| CVE-2026-82369 | Sep 23, 2026 |
Brocade SANnav <3.0.1a: CLI Scripting Shell Metachar BreakoutInsufficient input sanitization of shell metacharacters in the Brocade SANnav CLI scripting component permits authenticated users to break out of restricted execution contexts on managed switches. An attacker with command execution permissions can leverage this flaw to run unauthorized shell commands across target fabric switches, bypassing command allow-lists and obtaining full administrative switch access. This vulnerability affects all Brocade SANnav versions before 3.0.1a. |
|
| CVE-2026-82368 | Sep 23, 2026 |
Brocade SANnav <3.0.1a Insecure Internal Port Access (Local User)Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly with backend management services. A local attacker can leverage this exposed access to transmit commands to connected Fabric OS switches under the security context of the SANnav management user. |
|
| CVE-2019-25747 | Jun 19, 2026 |
Network Inventory Advisor 5.0.26.0 Unquoted Binary Path Escalation in niaserviceNetwork Inventory Advisor 5.0.26.0 installs the niaservice service with an unquoted binary path that allows local attackers to escalate privileges by placing malicious executables in intermediate directories. Attackers can exploit the unquoted path in the service configuration to execute arbitrary code with LocalSystem privileges when the service starts or restarts. |
|
| CVE-2026-0869 | Mar 03, 2026 |
Brocade ASCG 3.4.0 Auth bypass via BSL config opsAuthentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Brocade Support Link(BSL) and streaming configuration. and could even disable the ASCG application or disable use of BSL data collection on Brocade switches within the fabric. |
|
| CVE-2025-58381 | Feb 03, 2026 |
Brocade Fabric OS <9.2.1c2 PATH var modification via shell cmdsA vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using the shell commands source, ping6, sleep, disown, wait to modify the path variables and move upwards in the directory structure or to traverse to different directories. |
|
| CVE-2025-9711 | Feb 03, 2026 |
Privilege Escalation in Brocade Fabric OS <9.2.1c3 via seccertmgmt ExportA vulnerability in Brocade Fabric OS before 9.2.1c3 could allow elevating the privileges of the local authenticated user to root using the export option of seccertmgmt and seccryptocfg commands. |
|
| CVE-2025-58380 | Feb 03, 2026 |
Brocade Fabric OS <9.2.1: grep path traversal with adminA vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the shell command grep to modify the path variables and move upwards in the directory structure or to traverse to different directories. |
|
| CVE-2026-0383 | Feb 03, 2026 |
Local Auth Bash History Exposure in Brocade Fabric OSA vulnerability in Brocade Fabric OS could allow an authenticated, local attacker with privileges to access the Bash shell to access insecurely stored file contents including the history command. |
|
| CVE-2025-58379 | Feb 03, 2026 |
Brocade Fabric OS <=9.2.1 Local Auth Attacker Reveals Cmd Line PasswdsBrocade Fabric OS before 9.2.1 has a vulnerability that could allow a local authenticated attacker to reveal command line passwords using commands that may expose higher privilege sensitive information by a lower privileged user. |
|
| CVE-2025-58383 | Feb 03, 2026 |
Brocade Fabric OS <9.2.1c2 Priv Esc via bind CommandA vulnerability in Brocade Fabric OS versions before 9.2.1c2 could allow an administrator-level user to execute the bind command, to escalate privileges and bypass security controls allowing the execution of arbitrary commands. |
|
| CVE-2025-58382 | Feb 03, 2026 |
Brocade Fabric OS <9.2.1c2: Authenticated RCE via supportsaveA vulnerability in the secure configuration of authentication and management services in Brocade Fabric OS before Fabric OS 9.2.1c2 could allow an authenticated, remote attacker with administrative credentials to execute arbitrary commands as root using supportsave, seccertmgmt, configupload command. |
|
| CVE-2025-12774 | Feb 03, 2026 |
Brocade SANnav <3.0 migration script SQL queries info disclosureA vulnerability in the migration script for Brocade SANnav before 3.0 could allow the collection of database sql queries in the SANnav support save file. An attacker with access to Brocade SANnav supportsave file, could open the file and then obtain sensitive information such as details of database tables and encrypted passwords. |
|
| CVE-2025-12773 | Feb 03, 2026 |
Brocade SANnav password logging in updatereportspurgesettings.sh <2.4.0aA vulnerability in update-reports-purge-settings.sh script logging for Brocade SANnav before 2.4.0a could allow the collection of SANnav database password in the system audit logs. The vulnerability could allow a remote authenticated attacker with access to the audit logs to access the Brocade SANnav database password. |
|
| CVE-2025-12772 | Feb 02, 2026 |
Brocade SANnav <=2.4.0b Exposes Switch Admin Password via Logs (CVE-2025-12772)Brocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM occurs on a Brocade SANnav server, the call stack trace for the Brocade switch is also collected in the heap dump file which contains this switch password in clear text. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave to read the switch admin password. |
|
| CVE-2025-12679 | Feb 02, 2026 |
Brocade SANnav <2.4.0b: PBE Key Logged in System AuditA vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the system audit log file. The vulnerability could allow a remote authenticated attacker with access to the audit logs to access the pbe key. Note: The vulnerability is only triggered during a migration and not in a new installation. The system audit logs are accessible only to a privileged user on the server. These audit logs are the local server VMs audit logs and are not controlled by SANnav. These logs are only visible to the server admin of the host server and are not visible to the SANnav admin or any SANnav user. |
|
| CVE-2025-12680 | Feb 02, 2026 |
Brocade SANnav <2.4.0b: Standby Logs Store DB Passwords in Clear TextBrocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave to read the database password. |
|
| CVE-2025-4661 | Jun 19, 2025 |
Brocade Fabric OS 9.1.0-9.2.2 Path Traversal Exposes FilesA path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain access to files outside the intended directory potentially leading to the disclosure of sensitive information. Note: Admin level privilege is required on the switch in order to exploit |
|
| CVE-2025-1976 | Apr 24, 2025 |
Brocade Fabric OS 9.1.0–9.1.1d6 Local Admin Arbitrary Code ExecBrocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6. |
|
| CVE-2024-5462 | Feb 15, 2025 |
Brocade Fabric OS <9.2 SNMP Passwords Exposed via SNMPv3If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed in a configupload capture or a supportsave capture if encryption of passwords is not enabled. An attacker can use these passwords to fetch values of the supported OIDs via SNMPv3 queries. There are also a limited number of MIB objects that can be modified. |
|
| CVE-2024-7517 | Nov 21, 2024 |
Brocade Fabric OS Command Injection Vulnerability in Portcfg CommandA command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This specific exploitation is only possible on IP Extension platforms: Brocade 7810, Brocade 7840, Brocade 7850 and on Brocade X6 or X7 directors with an SX-6 Extension blade installed. The attacker must be logged into the switch via SSH or serial console to conduct the attack. |
|
| CVE-2024-10403 | Nov 21, 2024 |
Brocade Fabric OS SFTP/FTP Server Password Exposure in Core DumpBrocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operation initiated by SANnav or through WebEM in a weblinker core dump that is later captured via supportsave. |
|
| CVE-2024-5460 | Jun 26, 2024 |
Auth Remote SNMP Read Hard-Coded Community String in Brocade Fabric OS <9.0.0A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could allow an authenticated, remote attacker to read data from an affected device via SNMP. The vulnerability is due to hard-coded, default community string in the configuration file for the SNMP daemon. An attacker could exploit this vulnerability by using the static community string in SNMP version 1 queries to an affected device. |
|
| CVE-2024-29953 | Jun 26, 2024 |
Brocade Fabric OS <=9.2.1: Session Password DisclosureA vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords. |
|
| CVE-2023-5973 | Apr 05, 2024 |
Brocade Fabric OS v9.x Web UI Display Alteration via Reserved CharactersBrocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade Switch and change ports display. |
|
| CVE-2023-3454 | Apr 04, 2024 |
Brocade Fabric OS RCE v9.0-9.1.9 SwitchRemote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use this to gain root access to the Brocade switch. |
|
| CVE-2021-27795 | Dec 06, 2023 |
Brocade FOS License Forgery CVE-2021-27795Brocade Fabric OS (FOS) hardware platforms running any version of Brocade Fabric OS software, which supports the license string format; contain cryptographic issues that could allow for the installation of forged or fraudulent license keys. This would allow attackers or a malicious party to forge a counterfeit license key that the Brocade Fabric OS platform would authenticate and activate as if it were a legitimate license key. |
|
| CVE-2023-4162 | Aug 31, 2023 |
Segfault via passwdcfg in Brocade Fabric OS 9.0-9.2.0a CLIA segmentation fault can occur in Brocade Fabric OS after Brocade Fabric OS v9.0 and before Brocade Fabric OS v9.2.0a through the passwdcfg command. This could allow an authenticated privileged user local user to crash a Brocade Fabric OS swith using the cli passwdcfg --set -expire -minDiff. |
|
| CVE-2023-4163 | Aug 31, 2023 |
Brocade Fabric OS <9.2.0a Buffer Overflow via portcfgfportbuffersIn Brocade Fabric OS before v9.2.0a, a local authenticated privileged user can trigger a buffer overflow condition, leading to a kernel panic with large input to buffers in the portcfgfportbuffers command. |
|
| CVE-2023-3489 | Aug 31, 2023 |
Brocade Fabric OS 9.2.0 firmwaredownload logs cleartext passwordsThe firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in the SupportSave file when performing a downgrade from Fabric OS v9.2.0 to any earlier version of Fabric OS. |
|
| CVE-2023-31927 | Aug 02, 2023 |
Brocade Fabric OS <=9.1.1c Web UI Info DisclosureAn information disclosure in the web interface of Brocade Fabric OS versions before Brocade Fabric OS v9.2.0 and v9.1.1c, could allow a remote unauthenticated attacker to get technical details about the web interface. |
|
| CVE-2023-31428 | Aug 02, 2023 |
Brocade Fabric OS prev9.1.1c/v9.2.0: Local User Reads Home Dir via grepBrocade Fabric OS before Brocade Fabric OS v9.1.1c, v9.2.0 contains a vulnerability in the command line that could allow a local user to dump files under user's home directory using grep. |
|
| CVE-2023-31430 | Aug 02, 2023 |
Brocade FabricOS Secpolicydelete Buffer Overflow for Auth (pre 9.1.1c/9.2.0)A buffer overflow vulnerability in secpolicydelete command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0 could allow an authenticated privileged user to crash the Brocade Fabric OS switch leading to a denial of service. |
|
| CVE-2023-31431 | Aug 02, 2023 |
Brocade Fabric OS v<9.2.0 Buffer Overflow diagstatus (DoS)A buffer overflow vulnerability in diagstatus command in Brocade Fabric OS before Brocade Fabric v9.2.0 and v9.1.1c could allow an authenticated user to crash the Brocade Fabric OS switch leading to a denial of service. |
|
| CVE-2023-31432 | Aug 02, 2023 |
Brocade Fabric OS 9.1.1c: Priv Esc via portcfgupload & ConfigThrough manipulation of passwords or other variables, using commands such as portcfgupload, configupload, license, myid, a non-privileged user could obtain root privileges in Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c and v9.2.0. |
|
| CVE-2023-31425 | Aug 01, 2023 |
Priv Escalation via fosexec in Brocade FoOS <9.1.1A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS v9.1.1 could allow a local authenticated user to perform privilege escalation to root by breaking the rbash shell. Starting with Fabric OS v9.1.0, root account access is disabled. |
|
| CVE-2023-31429 | Aug 01, 2023 |
Brocade Fabric OS <=9.1.1c & 9.2.0 Output Leak via shell var interpolationBrocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as chassisdistribute, reboot, rasman, errmoduleshow, errfilterset, hassiscfgperrthreshold, supportshowcfgdisable and supportshowcfgenable commands that can cause the content of shell interpreted variables to be printed in the terminal. |
|
| CVE-2022-33186 | Dec 08, 2022 |
Broca FabricOS v9.x/v8.x/v7.x Remote Unauth Exec (Zoning/Port Disable)A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric OS switch commands capable of modifying zoning, disabling the switch, disabling ports, and modifying the switch IP address. |
|
| CVE-2022-33184 | Oct 25, 2022 |
Local Auth Root Exploit: Stack Buffer Overflow in Brocade Fabric OS <9.1.1A vulnerability in fab_seg.c.h libraries of all Brocade Fabric OS versions before Brocade Fabric OS v9.1.1, v9.0.1e, v8.2.3c, v8.2.0_cbn5, 7.4.2j could allow local authenticated attackers to exploit stack-based buffer overflows and execute arbitrary code as the root user account. |
|
| CVE-2022-33185 | Oct 25, 2022 |
Brocade Fabric OS <9.0.1e & <9.1.0 stack overflow (CVE-2022-33185)Several commands in Brocade Fabric OS before Brocade Fabric OS v.9.0.1e, and v9.1.0 use unsafe string functions to process user input. Authenticated local attackers could abuse these vulnerabilities to exploit stack-based buffer overflows, allowing arbitrary code execution as the root user account. |
|
| CVE-2022-33183 | Oct 25, 2022 |
Brocade Fabric OS CLI Buffer Overflow <v9.1.0A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a remote authenticated attacker to perform stack buffer overflow using in firmwaredownload and diagshow commands. |
|
| CVE-2022-33181 | Oct 25, 2022 |
Brocade Fabric OS CLI Local Info Disclosure via configshow & supportlink pre-9.1.0An information disclosure vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a local authenticated attacker to read sensitive files using switch commands configshow and supportlink. |
|
| CVE-2022-33180 | Oct 25, 2022 |
Brocade Fabric OS CLI <= v9.1.0 Export Sensitive Files via seccryptocfgA vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5 could allow a local authenticated attacker to export out sensitive files with seccryptocfg, configupload. |
|
| CVE-2022-33179 | Oct 25, 2022 |
Brocade Fabric OS CLI Local Auth Escalation Prior to v9.1.0A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, and 7.4.2j could allow a local authenticated user to break out of restricted shells with set context and escalate privileges. |
|