VulnerabilityModified
CVE-2023-5973
This could allow an authenticated user to alter the UI of the Brocade Switch and change ports display.
MEDIUM 4.3EPSS 0.18%
Does this matter?
Lower severity and a low EPSS score (0.18%). Track it; it rarely justifies an emergency change on its own.
Description
Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade Switch and change ports display.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.18% probability · 8th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-346
- Affected
- broadcom/fabric operating system
- Source
- sirt@brocade.com
References
- https://security.netapp.com/advisory/ntap-20240628-0005/Third Party Advisory
- https://support.broadcom.com/external/content/SecurityAdvisories/0/23214Vendor Advisory
- https://security.netapp.com/advisory/ntap-20240628-0005/Third Party Advisory
- https://support.broadcom.com/external/content/SecurityAdvisories/0/23214Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.