CVE-2025-1976
KEVmoderateAdmin-to-Root Privilege Escalation in Broadcom Brocade Fabric OS 9.1
CISA: Broadcom Brocade Fabric OS Code Injection Vulnerability
CVE-2025-1976 is a code/command injection flaw (CWE-94, CWE-78) in Broadcom Brocade Fabric OS, the operating system running on Brocade fibre-channel SAN switches. Starting with Fabric OS 9.1.0, root access was removed from administrators, but on versions 9.1.0 through 9.1.1d6 a local user with admin privileges can inject and execute arbitrary code to run with full root privileges. The CVSS 4.0 vector (AV:A/PR:L) indicates the attacker needs adjacent access with admin-level credentials and no user interaction, and successful exploitation grants complete root control of the switch, potentially compromising SAN fabric operations and enabling persistence in the storage network. Any organization running Brocade switches on the affected Fabric OS 9.1.0–9.1.1d6 range is exposed. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-04-28, confirming active exploitation; no public PoC is known and EPSS puts 30-day exploitation probability at 0.7%.
What to do: Upgrade Brocade Fabric OS to a release later than 9.1.1d6 following Brocade's security advisory; because the affected range ends at 9.1.1d6, any switch on 9.1.0–9.1.1d6 should be treated as vulnerable. Until patched, restrict admin CLI/SSH/API access to trusted administrators, audit admin accounts and CLI logs for signs of misuse, and hunt for unexpected code execution on switches. U.S. federal agencies must apply vendor mitigations or discontinue use per BOD 22-01 timelines, given the KEV listing.
| Broadcom Brocade Fabric OS | 9.1.0 through 9.1.1d6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.
- Affected
- Broadcom Brocade Fabric OS
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- broadcom
- Products
- fabric operating system
- Weakness
- CWE-94, CWE-78
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X