← Vulnerability feed

Vulnerability record · CVE-2025-1976 · published 24 April 2025

CVE-2025-1976: Brocade Fabric OS admin-to-root code injection

Broadcom · Fabric Operating System

Brocade Fabric OS 9.1.0 through 9.1.1d6 removed direct root access, but a local user with admin privilege can execute arbitrary code with full root privileges. This lets a privileged operator escalate to root on the switch, breaking the intended privilege separation.

8.6 CVSS 4.0 High CISA KEV since 28 Apr 2025 EPSS 0.69% · top 49.1% CWE-94 · Code injectionCWE-78 · OS command injection
8.6CVSS 4.0 base score
0.69%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.

CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityIt is in CISA KEV with a near-term remediation deadline and gives root-level code execution, though it requires an existing admin account and adjacent access.

What it is

Brocade Fabric OS 9.1.0 through 9.1.1d6 removed direct root access, but a local user with admin privilege can execute arbitrary code with full root privileges. This lets a privileged operator escalate to root on the switch, breaking the intended privilege separation.

Impact

An attacker with an existing admin account gains full root-level code execution on the Fabric OS device. That allows complete control of the switch, including configuration, data and any credentials or fabric operations it handles.

Attack surface

Reached locally on the device by an authenticated user holding admin privilege; the CVSS 4.0 vector is AV:A/PR:L/UI:N, so it is adjacent access with low privileges required and no user interaction.

Exploitation

CVE-2025-1976 is listed in CISA KEV with a 2025-05-19 remediation due date, indicating known exploitation, while EPSS is low at 0.00694 (51st percentile). No ransomware campaign use is documented.

What to do

  • Apply the Broadcom Brocade Fabric OS update that fixes the code injection; follow the vendor advisory for the correct fixed release.
  • If patching is not immediately possible, follow CISA KEV required action and vendor instructions, or discontinue use of the affected product.
  • Restrict and audit admin-privileged accounts on Fabric OS devices; remove unnecessary admin users and enforce least privilege.
  • Limit management access to trusted, adjacent network segments and monitor for unexpected local command execution.
  • Track the CISA KEV due date (2025-05-19) and confirm remediation before it passes.

Detection

  • Audit Fabric OS logs for admin sessions spawning unexpected shell or command execution activity.
  • Alert on new or modified local accounts and privilege changes on Fabric OS devices.
  • Monitor for anomalous commands or process behavior originating from admin sessions on switches.
  • Review authentication and command audit logs for admin activity outside normal change windows.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-1976 to the Known Exploited Vulnerabilities catalog on 28 April 2025 as "Broadcom Brocade Fabric OS Code Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 19 May 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-1976 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-3454Broadcom fabric operating system os command injection vulnerabilityRemote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use…EPSS 1.2%9.8CVE-2022-33186Broadcom fabric operating system os command injection vulnerabilityA vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker t…EPSS 1.6%9.8CVE-2021-27797Broadcom fabric operating system hard-coded credentials vulnerabilityBrocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded cred…EPSS 1.3%9.8CVE-2020-15371Broadcom fabric operating system code injection vulnerabilityBrocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, contains code injection and privilege escalation …EPSS 1.3%9.8CVE-2020-15373Broadcom fabric operating system memory buffer overflow vulnerabilityMultiple buffer overflow vulnerabilities in REST API in Brocade Fabric OS versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c could al…EPSS 2.4%9.8CVE-2020-15374Broadcom fabric operating system vulnerabilityRest API in Brocade Fabric OS v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c is vulnerable to multiple instances of reflected input.EPSS 1.2%9.8CVE-2019-18805Linux kernel integer overflow vulnerabilityAn issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in t…EPSS 3.4%9.1CVE-2018-6440Broadcom fabric operating system vulnerabilityA vulnerability in the proxy service of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow remote unauthenticated attackers …EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2025-1976), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.