GHSA-ph5j-f53x-2pfjMedium
A stack-based buffer overflow vulnerability exists in the diagnostic execution utility of Brocade...
🔗 CVE IDs covered (1)
📋 Description
A stack-based buffer overflow vulnerability exists in the diagnostic execution utility of Brocade Fabric OS versions before 10.0.1. When processing command arguments for diagnostic operations, the utility tokenizes user-supplied input into an internal argument array without enforcing boundary checks on the maximum array capacity. An authenticated user with administrative access can exploit this vulnerability by supplying a crafted diagnostic command string containing an excessive number of tokenized arguments. This leads to a memory overwrite resulting in a denial of service (process crash).