First published: Sat Feb 15 2025(Updated: )
Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform command or parameter injection on SNMP operations that are only enabled on the Brocade 6547 (FC5022) embedded switch. This injection could allow the authenticated attacker to issue commands as Root.
Credit: sirt@brocade.com
Affected Software | Affected Version | How to fix |
---|---|---|
Brocade 6547 (FC5022) embedded switch |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5461 has been classified as a high-severity vulnerability due to the potential for command or parameter injection.
Mitigation for CVE-2024-5461 involves updating the Brocade 6547 (FC5022) embedded switch to the latest firmware that addresses this vulnerability.
CVE-2024-5461 specifically affects the Brocade 6547 (FC5022) embedded switch.
CVE-2024-5461 allows authenticated attackers to perform command or parameter injection attacks.
Yes, CVE-2024-5461 requires the attacker to have authentication to exploit the vulnerability.