LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-1976: Broadcom Brocade Fabric OS Code Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 28, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 19, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-1976 to its Known Exploited Vulnerabilities catalog on Apr 28, 2025, with a federal patch deadline of May 19, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Broadcom Brocade Fabric OS contains a code injection vulnerability that allows a local user with administrative privileges to execute arbitrary code with full root privileges.

CVE-2025-1976 is a code injection vulnerability in Broadcom Brocade Fabric OS. According to CISA, it allows a local user who already holds administrative privileges to execute arbitrary code with full root privileges. This matters because Fabric OS runs on storage-area-network (SAN) switches that sit at the core of many enterprise storage fabrics; a successful exploit can give an attacker complete control of the switch and, by extension, visibility into or disruption of the storage traffic it carries. Teams that operate Brocade-based fabrics should treat the issue as high priority and confirm every detail against the vendor advisory.

How it works

The weakness is classified as CWE-94 (Improper Control of Generation of Code, or “code injection”). In products of this class an attacker who can already authenticate with administrative rights supplies input that the operating system later interprets as executable code rather than as data. Because the process runs with elevated privileges, the injected code executes as root. The CISA summary states that only a local administrative user can trigger the flaw; remote unauthenticated exploitation is not described. Exact injection vectors, command syntax, or payload formats are not provided in the public summary and must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

Brocade Fabric OS is the embedded operating system on Broadcom/Brocade Fibre Channel switches and directors commonly found in data-center SAN environments. Inventory steps include:

If your environment uses cloud-hosted or managed Brocade services, also follow any BOD 22-01 guidance that applies to those offerings.

How to remediate

The primary remediation is to apply the vendor-supplied update that addresses CVE-2025-1976. Obtain the fixed Fabric OS image from Broadcom, validate its integrity, and follow the documented upgrade procedure for your switch model and fabric topology. After the upgrade, re-verify the version string and confirm that the administrative interface no longer accepts the previously vulnerable input patterns (again, details are in the advisory).

Additional hardening steps appropriate for this class of device include:

If mitigations are unavailable for a particular platform, CISA advises discontinuing use of the product.

If you can't patch immediately

Until the vendor update can be installed, reduce risk with compensating controls:

These measures do not eliminate the vulnerability but limit the window of opportunity for an already-privileged local attacker.

If your data may have been exposed

Actively exploited vulnerabilities of this severity can lead to full compromise of the affected switch and potential exposure of storage-fabric traffic or credentials stored on the device. Known ransomware use of CVE-2025-1976 is not documented. If you suspect compromise, preserve logs, isolate the switch, and follow your incident-response plan. Separately, you can run a free exposure scan of your email address to check whether credentials or personal data associated with your organization already appear in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedBroadcom · Brocade Fabric OS
WeaknessCWE-94
Added to CISA KEVApr 28, 2025
Federal patch deadlineMay 19, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities