Code Injection in Brocade Fabric OS - CVE-2025-1976
Published: April 22, 2025
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper validation of IP addresses. A local user with admin-level privileges can pass a specially crafted IP address and execute arbitrary code on the system with root privileges.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Connectrix (Brocade)
How to mitigate CVE-2025-1976
Connectrix (Brocade) - update to 9.1.1d7