Vulnerability record · CVE-2025-1976 · published 24 April 2025
CVE-2025-1976: Brocade Fabric OS admin-to-root code injection
Broadcom · Fabric Operating System
Brocade Fabric OS 9.1.0 through 9.1.1d6 removed direct root access, but a local user with admin privilege can execute arbitrary code with full root privileges. This lets a privileged operator escalate to root on the switch, breaking the intended privilege separation.
Description
Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
high priorityIt is in CISA KEV with a near-term remediation deadline and gives root-level code execution, though it requires an existing admin account and adjacent access.
What it is
Brocade Fabric OS 9.1.0 through 9.1.1d6 removed direct root access, but a local user with admin privilege can execute arbitrary code with full root privileges. This lets a privileged operator escalate to root on the switch, breaking the intended privilege separation.
Impact
An attacker with an existing admin account gains full root-level code execution on the Fabric OS device. That allows complete control of the switch, including configuration, data and any credentials or fabric operations it handles.
Attack surface
Reached locally on the device by an authenticated user holding admin privilege; the CVSS 4.0 vector is AV:A/PR:L/UI:N, so it is adjacent access with low privileges required and no user interaction.
Exploitation
CVE-2025-1976 is listed in CISA KEV with a 2025-05-19 remediation due date, indicating known exploitation, while EPSS is low at 0.00694 (51st percentile). No ransomware campaign use is documented.
What to do
- Apply the Broadcom Brocade Fabric OS update that fixes the code injection; follow the vendor advisory for the correct fixed release.
- If patching is not immediately possible, follow CISA KEV required action and vendor instructions, or discontinue use of the affected product.
- Restrict and audit admin-privileged accounts on Fabric OS devices; remove unnecessary admin users and enforce least privilege.
- Limit management access to trusted, adjacent network segments and monitor for unexpected local command execution.
- Track the CISA KEV due date (2025-05-19) and confirm remediation before it passes.
Detection
- Audit Fabric OS logs for admin sessions spawning unexpected shell or command execution activity.
- Alert on new or modified local accounts and privilege changes on Fabric OS devices.
- Monitor for anomalous commands or process behavior originating from admin sessions on switches.
- Review authentication and command audit logs for admin activity outside normal change windows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-1976 to the Known Exploited Vulnerabilities catalog on 28 April 2025 as "Broadcom Brocade Fabric OS Code Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 19 May 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25602 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-1976 | US Government Resource |
Track CVE-2025-1976 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-1976), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.