CVE-2026-87665
Received Received - Intake

Stack-Based Buffer Overflow in Brocade Fabric OS IKEv2 Handler

Vulnerability report for CVE-2026-87665, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

A stack-based buffer overflow vulnerability exists in the Internet Key Exchange (IKEv2) protocol handler on Brocade Fabric OS versions before 10.0.1. The vulnerability occurs when processing initial IKE key exchange requests on extension switches or blades running IPsec-enabled Fibre Channel over IP (FCIP) circuits. An unauthenticated remote attacker can exploit this vulnerability by sending a single, specifically crafted UDP packet (Port 500) containing an oversized Nonce payload. Successful exploitation results in a denial of service (data-plane process crash)

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Brocade Fabric OS 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stack-based buffer overflow in Brocade Fabric OS versions before 10.0.1 affecting the IKEv2 protocol handler. It occurs when processing oversized Nonce payloads in initial IKE key exchange requests on extension switches or blades running IPsec-enabled FCIP circuits. An unauthenticated remote attacker can crash the data-plane process by sending a single crafted UDP packet to port 500.

Detection Guidance

Detecting this vulnerability requires monitoring for unusual traffic on UDP port 500, especially oversized Nonce payloads in IKEv2 packets. Use network monitoring tools like tcpdump or Wireshark to capture and analyze IKEv2 traffic for malformed packets targeting Brocade Fabric OS devices.

Impact Analysis

The vulnerability allows an attacker to cause a denial of service by crashing the data-plane process on affected Brocade devices. This could disrupt network services, including IPsec-enabled Fibre Channel over IP circuits, leading to loss of connectivity or data access for users and systems relying on these services.

Compliance Impact

This vulnerability primarily causes a denial of service by crashing the data-plane process, which could disrupt network services. It does not directly affect data confidentiality or integrity, so its impact on GDPR or HIPAA compliance is likely minimal unless service disruption leads to secondary compliance issues.

Mitigation Strategies

Immediately upgrade Brocade Fabric OS to version 10.0.1 or later. Block or restrict UDP port 500 traffic at the network perimeter if not required. Apply firewall rules to filter malformed IKEv2 packets. Monitor for exploit attempts and disable IPsec-enabled FCIP circuits if not in use.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87665. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart