CVE-2026-87671: High severity Brocade Fabric OS vulnerability
An out-of-bounds memory read vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1. Unauthenticated HTTP endpoints process specific URL query parameters without validating array index boundaries or performing numerical range checks. An unauthenticated remote attacker can exploit this issue by sending a single, crafted HTTP request containing extreme numerical values in the query string. This causes an invalid memory dereference, resulting in a crash of the web management process (Denial of Service) and potential temporary management-plane disruption.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 10.0.1
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Brocade Fabric OS versions before 10.0.1 are affected where the web management daemon and its HTTP endpoints are reachable by an attacker. The issue affects the management plane rather than data confidentiality or integrity.
Does exploitation require authentication or user interaction?
No. An unauthenticated remote attacker can trigger the issue with a single crafted HTTP request, and no user interaction is required.
What is the expected impact of a successful attack?
Successful exploitation crashes the web management process, causing a denial of service and potentially temporary disruption of management-plane access. The provided information does not indicate an impact on confidentiality or integrity.
What input is used to trigger the vulnerability?
The attack uses extreme numerical values in URL query-string parameters handled by unauthenticated HTTP endpoints. These values cause an out-of-bounds memory read through invalid array indexing or missing numerical range validation.