CVE-2022-33182: High severity broadcom fabric operating system vulnerability
A privilege escalation vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, could allow a local authenticated user to escalate its privilege to root using switch commands “supportlink”, “firmwaredownload”, “portcfgupload, license, and “fosexec”.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-33182.
What is the severity of CVE-2022-33182?
The severity of CVE-2022-33182 is high with a CVSS score of 7.8.
Which software versions are affected by CVE-2022-33182?
Brocade Fabric OS versions between 8.0.0 and 8.2.3c, as well as versions between 9.0.0 and 9.0.1e are affected.
How can a local authenticated user exploit CVE-2022-33182?
By using specific switch commands such as "supportlink", "firmwaredownload", "portcfgupload", "license", and "fosexec", a local authenticated user can escalate their privilege to root.
Is there a patch available for CVE-2022-33182?
Yes, updating to Brocade Fabric OS v9.1.0 or later will fix the vulnerability.