CVE-2024-5461 Details
Description
Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform command or parameter injection on SNMP operations that are only enabled on the Brocade 6547 (FC5022) embedded switch. This injection could allow the authenticated attacker to issue commands as Root.
A command or parameter injection vulnerability has been identified in the Simple Network Management Protocol (SNMP) implementation on Brocade 6547 (FC5022) embedded switch blades, running Fabric OS prior to 8.2.3e1_pha. The vulnerability arises because the SNMP binary makes internal script calls to system.sh, allowing authenticated attackers to inject commands into SNMP operations unique to this switch model. Exploitation of this vulnerability could enable attackers to execute commands with root privileges.
Users can upgrade to Brocade Fabric OS 8.2.3e1_pha to address this vulnerability, as this patch release removes the vulnerable component from the code.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24411 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| broadcom fabric operating system | < 8.2.3e1 |
CPE
Remediation
| |
| broadcom brocade 6547 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 23, 2026 | Initial Analysis | [email protected] |
| Sep 9, 2025 | CVE Modified | [email protected] |
| Feb 15, 2025 | New CVE Received | [email protected] |