CVE-2026-87665

MEDIUM CVSS 4.0: 6.0
Updated Oct 08, 2026
Payload
Parameter Value
CVSS 6.0 (MEDIUM)
Affected Versions before 10.0.1.
Type CWE-121 (Stack-based Buffer Overflow)
Vendor Payload
Public PoC No

A stack-based buffer overflow vulnerability exists in the Internet Key Exchange (IKEv2) protocol handler on Brocade Fabric OS versions before 10.0.1. The vulnerability occurs when processing initial IKE key exchange requests on extension switches or blades running IPsec-enabled Fibre Channel over IP (FCIP) circuits. An unauthenticated remote attacker can exploit this vulnerability by sending a single, specifically crafted UDP packet (Port 500) containing an oversized Nonce payload.

Successful exploitation results in a denial of service (data-plane process crash)

Attack Parameters

Attack Vector
Adjacent
Requires local network access
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
High
Complete denial of service

CVSS Vector v4.0