brocade CVE Vulnerabilities & Metrics

Focus on brocade vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About brocade Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with brocade. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total brocade CVEs: 21
Earliest CVE date: 04 Sep 2004, 04:00 UTC
Latest CVE date: 31 Aug 2023, 01:15 UTC

Latest CVE reference: CVE-2023-4162

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical brocade CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.12

Max CVSS: 10.0

Critical CVEs (≥9): 3

CVSS Range vs. Count

Range Count
0.0-3.9 5
4.0-6.9 18
7.0-8.9 2
9.0-10.0 3

CVSS Distribution Chart

Top 5 Highest CVSS brocade CVEs

These are the five CVEs with the highest CVSS scores for brocade, sorted by severity first and recency.

All CVEs for brocade

CVE-2023-4162 brocade vulnerability CVSS: 0 31 Aug 2023, 01:15 UTC

A segmentation fault can occur in Brocade Fabric OS after Brocade Fabric OS v9.0 and before Brocade Fabric OS v9.2.0a through the passwdcfg command. This could allow an authenticated privileged user local user to crash a Brocade Fabric OS swith using the cli “passwdcfg --set -expire -minDiff“.

CVE-2022-33186 brocade vulnerability CVSS: 0 08 Dec 2022, 22:15 UTC

A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric OS switch commands capable of modifying zoning, disabling the switch, disabling ports, and modifying the switch IP address.

CVE-2022-27776 brocade vulnerability CVSS: 4.3 02 Jun 2022, 14:15 UTC

A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

CVE-2022-27775 brocade vulnerability CVSS: 5.0 02 Jun 2022, 14:15 UTC

An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.

CVE-2022-27774 brocade vulnerability CVSS: 3.5 02 Jun 2022, 14:15 UTC

An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.

CVE-2022-22576 brocade vulnerability CVSS: 5.5 26 May 2022, 17:15 UTC

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

CVE-2021-22555 brocade vulnerability CVSS: 4.6 07 Jul 2021, 12:15 UTC

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

CVE-2020-13632 brocade vulnerability CVSS: 2.1 27 May 2020, 15:15 UTC

ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.

CVE-2020-13631 brocade vulnerability CVSS: 2.1 27 May 2020, 15:15 UTC

SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.

CVE-2020-13630 brocade vulnerability CVSS: 4.4 27 May 2020, 15:15 UTC

ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.

CVE-2018-6445 brocade vulnerability CVSS: 5.0 22 Jan 2019, 17:29 UTC

A Vulnerability in Brocade Network Advisor versions before 14.0.3 could allow a remote unauthenticated attacker to export the current user database which includes the encrypted (not hashed) password of the systems. The attacker could gain access to the Brocade Network Advisor System after extracting/decrypting the passwords.

CVE-2018-6444 brocade vulnerability CVSS: 10.0 22 Jan 2019, 17:29 UTC

A Vulnerability in Brocade Network Advisor versions before 14.1.0 could allow a remote unauthenticated attacker to execute arbitray code. The vulnerability could also be exploited to execute arbitrary OS Commands.

CVE-2018-6443 brocade vulnerability CVSS: 4.3 22 Jan 2019, 17:29 UTC

A vulnerability in Brocade Network Advisor Versions before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentials and install additional JEE applications. A remote unauthenticated user who has access to Network Advisor client libraries and able to decrypt the Jboss credentials could gain access to the Jboss web console.

CVE-2017-6227 brocade vulnerability CVSS: 6.1 08 Feb 2018, 22:29 UTC

A vulnerability in the IPv6 stack on Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) versions before 7.4.2b, 8.1.2 and 8.2.0 could allow an attacker to cause a denial of service (CPU consumption and device hang) condition by sending crafted Router Advertisement (RA) messages to a targeted system.

CVE-2017-6225 brocade vulnerability CVSS: 4.3 08 Feb 2018, 22:29 UTC

Cross-site scripting (XSS) vulnerability in the web-based management interface of Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) versions before 7.4.2b, 8.1.2 and 8.2.0 could allow remote attackers to execute arbitrary code or access sensitive browser-based information.

CVE-2016-8209 brocade vulnerability CVSS: 5.0 08 May 2017, 18:29 UTC

Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2016-8207 brocade vulnerability CVSS: 5.0 14 Jan 2017, 19:59 UTC

A Directory Traversal vulnerability in CliMonitorReportServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to read arbitrary files including files with sensitive user information.

CVE-2016-8206 brocade vulnerability CVSS: 6.4 14 Jan 2017, 19:59 UTC

A Directory Traversal vulnerability in servlet SoftwareImageUpload in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to write to arbitrary files, and consequently delete the files.

CVE-2016-8205 brocade vulnerability CVSS: 10.0 14 Jan 2017, 19:59 UTC

A Directory Traversal vulnerability in DashboardFileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where it can be executed.

CVE-2016-8201 brocade vulnerability CVSS: 6.0 14 Jan 2017, 19:59 UTC

A CSRF vulnerability in Brocade Virtual Traffic Manager versions released prior to and including 11.0 could allow an attacker to trick a logged-in user into making administrative changes on the traffic manager cluster.

CVE-2016-8203 brocade vulnerability CVSS: 7.8 31 Oct 2016, 21:59 UTC

A memory corruption in the IPsec code path of Brocade NetIron OS on Brocade MLXs 5.8.00 through 5.8.00e, 5.9.00 through 5.9.00bd, 6.0.00, and 6.0.00a images could allow attackers to cause a denial of service (line card reset) via certain constructed IPsec control packets.

CVE-2014-4870 brocade vulnerability CVSS: 7.2 07 Oct 2014, 10:55 UTC

/opt/vyatta/bin/sudo-users/vyatta-clear-dhcp-lease.pl on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 does not properly validate parameters, which allows local users to gain privileges by leveraging the sudo configuration.

CVE-2014-4869 brocade vulnerability CVSS: 5.0 07 Oct 2014, 10:55 UTC

The Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows attackers to obtain sensitive encrypted-password information by leveraging membership in the operator group.

CVE-2014-4868 brocade vulnerability CVSS: 9.0 07 Oct 2014, 10:55 UTC

The management console on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows remote authenticated users to execute arbitrary Linux commands via shell metacharacters in a console command.

CVE-2013-7307 brocade vulnerability CVSS: 5.4 23 Jan 2014, 17:55 UTC

The OSPF implementation on the Brocade Vyatta vRouter with software before 6.6R1 does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

CVE-2013-7306 brocade vulnerability CVSS: 5.4 23 Jan 2014, 17:55 UTC

The OSPF implementation on Brocade routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

CVE-2011-2760 brocade vulnerability CVSS: 5.0 17 Jul 2011, 20:55 UTC

Brocade BigIron RX switches allow remote attackers to bypass ACL rules by using 179 as the source port of a packet.

CVE-2004-1663 brocade vulnerability CVSS: 5.0 04 Sep 2004, 04:00 UTC

Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets.