CVE-2024-5461: Command or parameter injection via unique embedded switch SNMP commands.
Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform command or parameter injection on SNMP operations that are only enabled on the Brocade 6547 (FC5022) embedded switch. This injection could allow the authenticated attacker to issue commands as Root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5461?
CVE-2024-5461 has been classified as a high-severity vulnerability due to the potential for command or parameter injection.
How can I mitigate CVE-2024-5461?
Mitigation for CVE-2024-5461 involves updating the Brocade 6547 (FC5022) embedded switch to the latest firmware that addresses this vulnerability.
What systems are affected by CVE-2024-5461?
CVE-2024-5461 specifically affects the Brocade 6547 (FC5022) embedded switch.
What type of attack can be executed through CVE-2024-5461?
CVE-2024-5461 allows authenticated attackers to perform command or parameter injection attacks.
Is authentication required to exploit CVE-2024-5461?
Yes, CVE-2024-5461 requires the attacker to have authentication to exploit the vulnerability.