CVE-2025-9711 PUBLISHED

Privilege escalation in Brocade Fabric OS before 9.2.1c3, and 9.2.2 though 9.2.2b

Assigner: brocade
Reserved: 29.08.2025 Published: 03.02.2026 Updated: 03.02.2026

A vulnerability in Brocade Fabric OS before 9.2.1c3 could allow elevating the privileges of the local authenticated user to “root” using the export option of seccertmgmt and seccryptocfg commands.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Brocade
Product Fabric OS
Versions Default: unaffected
  • Version before 9.2.1c3, and 9.2.2 though 9.2.2b is affected

References

Problem Types

  • CWE-272: Least Privilege Violation CWE

Impacts

  • CAPEC-233: Privilege Escalation