Back

HIGH

Command or parameter injection via unique embedded switch SNMP commands.

Published Feb 15, 2025

Description

Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform command or parameter injection on SNMP operations that are only enabled on the Brocade 6547 (FC5022) embedded switch. This injection could allow the authenticated attacker to issue commands as Root.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner brocade
Published Feb 15, 2025
Updated Sep 9, 2025
Reserved May 29, 2024

CISA Vulnrichment

Updated Feb 18, 2025

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner brocade
Published Feb 15, 2025
Updated Sep 9, 2025

GitHub

No data