VYPR
Unrated severityNVD Advisory· Published Aug 5, 2022· Updated Feb 15, 2025

privileged directory transversal.in Brocade Fabric OS versions 7.4.1.x and 7.3.x

CVE-2021-27798

Description

A vulnerability in Brocade Fabric OS versions 7.4.1b and 7.3.1d could allow local users to conduct privileged directory transversal. Brocade Fabric OS versions 7.4.1.x and 7.3.x have reached end of life. Brocade Fabric OS Users should upgrade to supported versions as described in the Product End-of-Life published report.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A privileged directory traversal vulnerability in Brocade Fabric OS 7.4.1b and 7.3.1d allows local users to list the entire filesystem via the 'more' binary with tab-completion.

Vulnerability

A privileged directory traversal vulnerability exists in Brocade Fabric OS versions 7.4.1b and 7.3.1d. Within the restricted shell environment (rbash), users logged in as either the "user" or "factory" account can leverage the more binary with tab-completion to list the entire filesystem. These versions have reached end of life (EOL) and are no longer supported [1].

Exploitation

An attacker requires local access via an active SSH session with a valid "user" or "factory" account. To exploit, the attacker types the command more and presses the TAB key repeatedly until a listing of the current directory appears. Alternatively, supplying partial paths such as more / or more /etc/ followed by pressing TAB will display the full contents of those directories [1].

Impact

Successful exploitation grants the attacker complete knowledge of the underlying filesystem structure, including all available binaries within the user's PATH environment variable. The listing is performed with root-equivalent permissions, leading to significant information disclosure [1].

Mitigation

Brocade Fabric OS versions 7.4.1b and 7.3.1d have reached End of Availability (EOA) and are no longer supported. No patch is available for these EOL versions. Users should upgrade to actively supported Brocade Fabric OS versions as recommended in the Product End-of-Life report [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.