Back

HIGH

Brocade Fabric OS before 9.2.2 does not enforce strict host key checking

Published Nov 12, 2024

Description

A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking that may arise from the attacker's ability to forge an SSH key while the Brocade Fabric OS Switch is performing various remote operations initiated by a switch admin.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner brocade
Published Nov 12, 2024
Updated Nov 21, 2024
Reserved Aug 5, 2024
CISA Vulnrichment
Updated Nov 13, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a