A stack-based buffer overflow vulnerability exists in the Internet Key Exchange (IKEv2) protocol handler on Brocade Fabric OS versions before 10.0.1. The vulnerability occurs when processing initial IKE key exchange requests on extension switches or blades running IPsec-enabled Fibre Channel over IP (FCIP) circuits. An unauthenticated remote attacker can exploit this vulnerability by sending a single, specifically crafted UDP packet (Port 500) containing an oversized Nonce payload. Successful exploitation results in a denial of service (data-plane process crash)
Advisories
No advisories yet.
Fixes
Solution
Security update is provided in Brocade Fabric OS 10.0.1
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Buffer Overflow in Brocade Fabric OS IKEv2 Handler Causes Data‑Plane Crash |
Thu, 08 Oct 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brocade
Brocade fabric Os |
|
| Vendors & Products |
Brocade
Brocade fabric Os |
Thu, 08 Oct 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack-based buffer overflow vulnerability exists in the Internet Key Exchange (IKEv2) protocol handler on Brocade Fabric OS versions before 10.0.1. The vulnerability occurs when processing initial IKE key exchange requests on extension switches or blades running IPsec-enabled Fibre Channel over IP (FCIP) circuits. An unauthenticated remote attacker can exploit this vulnerability by sending a single, specifically crafted UDP packet (Port 500) containing an oversized Nonce payload. Successful exploitation results in a denial of service (data-plane process crash) | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-10-08T02:58:44.774Z
Reserved: 2026-09-08T22:51:12.106Z
Link: CVE-2026-87665
No data.
Status : Received
Published: 2026-10-08T03:16:35.960
Modified: 2026-10-08T03:16:35.960
Link: CVE-2026-87665
No data.
OpenCVE Enrichment
Updated: 2026-10-08T05:00:15Z
Weaknesses