The host SSH servers of Brocade Fabric OS before Brocade Fabric OS v7.4.2h, v8.2.1c, v8.2.2, v9.0.0, and Brocade SANnav before v2.1.1 utilize keys of less than 2048 bits, which may be vulnerable to man-in-the-middle attacks and/or insecure SSH communications.
CVSS v4.0 Metrics
Exploitability
Attack VectorNetwork
ComplexityHigh
RequirementsPresent
PrivilegesNone
User InteractionNone
Threat
Exploit MaturityUnreported
Vulnerable System
ConfidentialityHigh
IntegrityHigh
AvailabilityNone
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Change Log
| Date | Source | Changes | Score |
|---|
| 2026-07-21 | nvd | AV: P→N, PR: H→N, UI: A→N, VC: N→H, VI: N→H | 0.0 → 6.9 |
| 2026-07-21 | cve.org | initial, patch: Unavailable | 0.0 |
Affected Software
| Vendor | Product | Version |
|---|
| broadcom | brocade_sannav | < 2.1.1 |
| broadcom | fabric_operating_system | ≥ 8.2.0, < 8.2.1 |
| broadcom | fabric_operating_system | < 7.4.2 |
| broadcom | fabric_operating_system | 7.4.2 |
| broadcom | fabric_operating_system | 7.4.2a |
| broadcom | fabric_operating_system | 7.4.2b |
| broadcom | fabric_operating_system | 7.4.2c |
| broadcom | fabric_operating_system | 7.4.2d |
| broadcom | fabric_operating_system | 7.4.2f |
| broadcom | fabric_operating_system | 7.4.2g |
| broadcom | fabric_operating_system | 8.2.1 |
| broadcom | fabric_operating_system | 8.2.1a |
| broadcom | fabric_operating_system | 8.2.1b |
| n/a | Brocade SANnav & Brocade Fabric OS | Brocade Fabric OS v7.4.2h, v8.2.1c, v8.2.2, v9.0.0 and Brocade SANnav v2.1.1 |
Published: 2021-06-09