CVE-2023-31425: Privilege escalation via the fosexec command
A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS v9.1.1 could allow a local authenticated user to perform privilege escalation to root by breaking the rbash shell. Starting with Fabric OS v9.1.0, “root” account access is disabled.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-31425?
CVE-2023-31425 is a vulnerability in the fosexec command of Brocade Fabric OS that allows a local authenticated user to perform privilege escalation to root by breaking the rbash shell.
What is the severity of CVE-2023-31425?
CVE-2023-31425 has a severity rating of 7.8, which is classified as high.
Which software versions are affected by CVE-2023-31425?
CVE-2023-31425 affects Brocade Fabric OS versions after v9.1.0 and before v9.1.1.
How can a local authenticated user exploit CVE-2023-31425?
To exploit CVE-2023-31425, a local authenticated user needs to break the rbash shell using the fosexec command in Brocade Fabric OS.
Are there any references for CVE-2023-31425?
Yes, you can find more information about CVE-2023-31425 at the following references: [Link 1](https://support.broadcom.com/external/content/SecurityAdvisories/0/22407), [Link 2](https://security.netapp.com/advisory/ntap-20230908-0007/).