privileged directory transversal.in Brocade Fabric OS versions 7.4.1.x and 7.3.x
Description
A vulnerability in Brocade Fabric OS versions 7.4.1b and 7.3.1d could allow local users to conduct privileged directory transversal. Brocade Fabric OS versions 7.4.1.x and 7.3.x have reached end of life. Brocade Fabric OS Users should upgrade to supported versions as described in the Product End-of-Life published report.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A privileged directory traversal vulnerability in Brocade Fabric OS 7.4.1b and 7.3.1d allows local users to list the entire filesystem via the 'more' binary with tab-completion.
Vulnerability
A privileged directory traversal vulnerability exists in Brocade Fabric OS versions 7.4.1b and 7.3.1d. Within the restricted shell environment (rbash), users logged in as either the "user" or "factory" account can leverage the more binary with tab-completion to list the entire filesystem. These versions have reached end of life (EOL) and are no longer supported [1].
Exploitation
An attacker requires local access via an active SSH session with a valid "user" or "factory" account. To exploit, the attacker types the command more and presses the TAB key repeatedly until a listing of the current directory appears. Alternatively, supplying partial paths such as more / or more /etc/ followed by pressing TAB will display the full contents of those directories [1].
Impact
Successful exploitation grants the attacker complete knowledge of the underlying filesystem structure, including all available binaries within the user's PATH environment variable. The listing is performed with root-equivalent permissions, leading to significant information disclosure [1].
Mitigation
Brocade Fabric OS versions 7.4.1b and 7.3.1d have reached End of Availability (EOA) and are no longer supported. No patch is available for these EOL versions. Users should upgrade to actively supported Brocade Fabric OS versions as recommended in the Product End-of-Life report [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.