ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Adds Actively Exploited Broadcom and Commvault Flaws to KEV Database

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-1976CVE-2025-3928

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-1976
Admin-to-Root Privilege Escalation in Broadcom Brocade Fabric OS 9.1

CVE-2025-1976 is a code/command injection flaw (CWE-94, CWE-78) in Broadcom Brocade Fabric OS, the operating system running on Brocade fibre-channel SAN switches. Starting with Fabric OS 9.1.0, root access was removed from administrators, but on versions 9.1.0 through 9.1.1d6 a local user with admin privileges can inject and execute arbitrary code to run with full root privileges. The CVSS 4.0 vector (AV:A/PR:L) indicates the attacker needs adjacent access with admin-level credentials and no user interaction, and successful exploitation grants complete root control of the switch, potentially compromising SAN fabric operations and enabling persistence in the storage network. Any organization running Brocade switches on the affected Fabric OS 9.1.0–9.1.1d6 range is exposed. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-04-28, confirming active exploitation; no public PoC is known and EPSS puts 30-day exploitation probability at 0.7%.

Do: Upgrade Brocade Fabric OS to a release later than 9.1.1d6 following Brocade's security advisory; because the affected range ends at 9.1.1d6, any switch on 9.1.0–9.1.1d6 should be treated as vulnerable. Until patched, restrict admin CLI/SSH/API access to trusted administrators, audit admin accounts and CLI logs for signs of misuse, and hunt for unexpected code execution on switches. U.S. federal agencies must apply vendor mitigations or discontinue use per BOD 22-01 timelines, given the KEV listing.

8.6<1% KEV
  • Broadcom Brocade Fabric OS 9.1.0 through 9.1.1d6
moderatelikely on the order of thousands to tens of thousands of SAN switches running FOS 9.1.0–9.1.1d6; exact counts unknown
CVE-2025-3928
Actively Exploited Authenticated Webshell Flaw in Commvault Web Server

CVE-2025-3928 is an unspecified vulnerability in the Commvault Web Server, the web administration component of Commvault's data protection platform, which can be exploited over the network by a remote attacker who holds valid (low-privilege) authenticated access. According to the Commvault advisory, attackers use the flaw to create and execute webshells on the web server, and the CVSS 4.0 score of 8.7 (High) reflects high impact to the confidentiality, integrity, and availability of the vulnerable web server component. It affects Commvault Web Server on both Windows and Linux across the supported release streams, with fixes delivered in 11.36.46, 11.32.89, 11.28.141, and 11.20.217. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-04-28, and Commvault has confirmed that hackers exploited it in the wild as a zero-day, with related reporting noting heightened Silk Typhoon (Chinese nation-state) attack activity. No public proof-of-concept is known, but the confirmed real-world zero-day exploitation makes patching urgent.

Do: Upgrade the Commvault Web Server to 11.36.46, 11.32.89, 11.28.141, or 11.20.217, matching your current release stream, on both Windows and Linux platforms. Because the flaw was exploited as a zero-day, hunt for attacker-created webshells and unexpected accounts, scripts, or scheduled tasks on Commvault web server hosts, review authentication logs for suspicious logins, and restrict the Commvault web interface to trusted networks. Federal agencies must apply vendor mitigations per CISA instructions or follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable.

8.72% KEV
  • Commvault Web Server Commvault Web Server on Windows and Linux, versions prior to the fixes in each supported release stream: 11.36 before 11.36.46, 11.32 before 11.32.89, 11.28 bef
large≈ tens of thousands of enterprise deployments worldwide (one Web Server per Commvault environment); internet-exposed instances likely in the thousands
Full article388 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananApr 29, 2025Vulnerability / Web Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added two high-severity security flaws impacting Broadcom Brocade Fabric OS and Commvault Web Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.

The vulnerabilities in question are listed below -

  • CVE-2025-1976 (CVSS score: 8.6) - A code injection flaw affecting Broadcom Brocade Fabric OS that allows a local user with administrative privileges to execute arbitrary code with full root privileges
  • CVE-2025-3928 (CVSS score: 8.7) - An unspecified flaw in the Commvault Web Server that allows a remote, authenticated attacker to create and execute web shells

"Exploiting this vulnerability requires a bad actor to have authenticated user credentials within the Commvault Software environment," Commvault said in an advisory released in February 2025.

"Unauthenticated access is not exploitable. For software customers, this means your environment must be: (i) accessible via the internet, (ii) compromised through an unrelated avenue, and (iii) accessed leveraging legitimate user credentials."

The vulnerability affects the following Windows and Linux versions -

  • 11.36.0 - 11.36.45 (Fixed in 11.36.46)
  • 11.32.0 - 11.32.88 (Fixed in 11.32.89)
  • 11.28.0 - 11.28.140 (Fixed in 11.28.141)
  • 11.20.0 - 11.20.216 (Fixed in 11.20.217)

As for CVE-2025-1976, Broadcom said that due to a flaw in IP Address validation, a local user with the admin privilege can potentially execute arbitrary code with root privileges on Fabric OS versions 9.1.0 through 9.1.1d6. It has been fixed in version 9.1.1d7.

"This vulnerability can allow the user to execute any existing Fabric OS command or can also be used to modify the Fabric OS itself, including adding their own subroutines," Broadcom noted in a bulletin published on April 17, 2025.

"Even though achieving this exploit first requires valid access to a role with admin privileges, this vulnerability has been actively exploited in the field."

There are currently no public details on how either of the vulnerabilities have been exploited in the wild, the scale of the attacks, and who may be behind them.

Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary patches for Commvault Web Server and Broadcom Brocade Fabric OS by May 19, 2025.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/04/cisa-adds-actively-exploited-broadcom.html