CVE-2024-5461

Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform command or parameter injection on SNMP operations that are only enabled on the Brocade 6547 (FC5022) embedded switch. This injection could allow the authenticated attacker to issue commands as Root.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:broadcom:fabric_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:h:broadcom:brocade_6547:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-02-15 00:15

Updated : 2026-02-23 14:53


NVD link : CVE-2024-5461

Mitre link : CVE-2024-5461

CVE.ORG link : CVE-2024-5461


JSON object : View

Products Affected

broadcom

  • fabric_operating_system
  • brocade_6547
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')