CVE-2026-94587: Buffer Overflow
A buffer overflow vulnerability exists in the WebTools administrative interface handling configuration download or file transfer operations of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with permissions to perform configuration downloads using remote server profiles can overflow stack buffers causing a crash of the weblinker daemon.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 9.2.2d - Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 10.0.1
Event History
Frequently Asked Questions
Which deployments are exposed?
Brocade Fabric OS versions before 9.2.2d and versions 10.0.0 through 10.0.0a1 are affected when the WebTools administrative interface is used for configuration download or file transfer operations with remote server profiles.
What access does an attacker need?
An attacker must already be authenticated and have permissions to perform configuration downloads using remote server profiles. No user interaction is required.
What is the practical impact of successful exploitation?
Successful exploitation can overflow stack buffers and crash the weblinker daemon, resulting in an availability impact. The provided CVSS vector indicates no confidentiality impact and low integrity impact.
What version should be used to remediate this issue?
Upgrade affected Fabric OS deployments to 9.2.2d or later. The affected 10.0.0 through 10.0.0a1 range should also be moved to a version outside that range.