← Vulnerability feed

Vulnerability record · CVE-2022-33186 · published 8 December 2022

CVE-2022-33186: Broadcom fabric operating system os command injection vulnerability

Broadcom · Fabric Operating System

A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric OS switch commands capable of modifying zoning, disabling the switch, disabling ports, and modifying the switch IP address.

9.8 CVSS 3.1 Critical EPSS 1.6% · top 25.2% CWE-78 · OS command injection
9.8CVSS 3.1 base score
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric OS switch commands capable of modifying zoning, disabling the switch, disabling ports, and modifying the switch IP address.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-33186 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2025-1976Brocade Fabric OS admin-to-root code injectionBrocade Fabric OS 9.1.0 through 9.1.1d6 removed direct root access, but a local user with admin privilege can execute arbitrary code with full root p…KEVEPSS 0.69%analysed7.8CVE-2021-22555Linux kernel netfilter x_tables heap out-of-bounds writeA heap out-of-bounds write exists in the Linux kernel netfilter x_tables code (net/netfilter/x_tables.c), present since v2.6.19-rc1. A local attacker…KEVEPSS 79%analysed9.8CVE-2023-3454Broadcom fabric operating system os command injection vulnerabilityRemote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use…EPSS 1.2%9.8CVE-2021-27797Broadcom fabric operating system hard-coded credentials vulnerabilityBrocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded cred…EPSS 1.3%9.8CVE-2020-15371Broadcom fabric operating system code injection vulnerabilityBrocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, contains code injection and privilege escalation …EPSS 1.3%9.8CVE-2020-15373Broadcom fabric operating system memory buffer overflow vulnerabilityMultiple buffer overflow vulnerabilities in REST API in Brocade Fabric OS versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c could al…EPSS 2.4%9.8CVE-2020-15374Broadcom fabric operating system vulnerabilityRest API in Brocade Fabric OS v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c is vulnerable to multiple instances of reflected input.EPSS 1.2%9.8CVE-2019-18805Linux kernel integer overflow vulnerabilityAn issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in t…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2022-33186), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.