← Vulnerability feed

Vulnerability record · CVE-2025-58382 · published 3 February 2026

CVE-2025-58382: Broadcom fabric operating system vulnerability

Broadcom · Fabric Operating System

A vulnerability in the secure configuration of authentication and management services in Brocade Fabric OS before Fabric OS 9.2.1c2 could allow an authenticated, remote attacker with administrative credentials to execute arbitrary commands as root using “supportsave”, “seccertmgmt”, “configupload” command.

8.5 CVSS 4.0 High EPSS 0.60% · top 53.5% CWE-305 · CWE-305
8.5CVSS 4.0 base score
0.60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the secure configuration of authentication and management services in Brocade Fabric OS before Fabric OS 9.2.1c2 could allow an authenticated, remote attacker with administrative credentials to execute arbitrary commands as root using “supportsave”, “seccertmgmt”, “configupload” command.

CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-58382 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2025-1976Brocade Fabric OS admin-to-root code injectionBrocade Fabric OS 9.1.0 through 9.1.1d6 removed direct root access, but a local user with admin privilege can execute arbitrary code with full root p…KEVEPSS 0.69%analysed9.8CVE-2023-3454Broadcom fabric operating system os command injection vulnerabilityRemote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use…EPSS 1.2%9.8CVE-2022-33186Broadcom fabric operating system os command injection vulnerabilityA vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker t…EPSS 1.6%9.8CVE-2021-27797Broadcom fabric operating system hard-coded credentials vulnerabilityBrocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded cred…EPSS 1.3%9.8CVE-2020-15371Broadcom fabric operating system code injection vulnerabilityBrocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, contains code injection and privilege escalation …EPSS 1.3%9.8CVE-2020-15373Broadcom fabric operating system memory buffer overflow vulnerabilityMultiple buffer overflow vulnerabilities in REST API in Brocade Fabric OS versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c could al…EPSS 2.4%9.8CVE-2020-15374Broadcom fabric operating system vulnerabilityRest API in Brocade Fabric OS v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c is vulnerable to multiple instances of reflected input.EPSS 1.2%9.8CVE-2019-18805Linux kernel integer overflow vulnerabilityAn issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in t…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2025-58382), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.