Latest Fabric OS vulnerability #
On April 4, 2024, Broadcom disclosed a vulnerability in their Fabric OS operating system used in their Brocade storage networking devices, affecting Fabric OS from version 9.0 up to (but not including) version 9.20.
CVE-2023-3454 is rated high with CVSS score of 8.6 and allows unauthenticated remote attackers to execute arbitrary code on vulnerable systems.
What is the impact? #
Successful exploitation of these vulnerabilities would allow an unauthenticated attacker to execute arbitrary code with root privileges on affected devices, potentially leading to total system compromise.
Are updates or workarounds available? #
Broadcom has advised users to update to Fabric OS version 9.20 as quickly as possible.
How to find potentially vulnerable systems with runZero #
From the Asset Inventory, use the following query to locate systems running potentially vulnerable software:
os:"Fabric OS"