GPU VulnDB

Database/Firmware, BMC & network fabric

Brocade Fabric OS Webtools (firmware update section): A remote authenticated attacker can abuse the Webtools

CVE-2018-6442Firmware, BMC & network fabriccurated

Impact

A remote authenticated attacker can abuse the Webtools firmware-update path. Firmware update on a SAN switch is the persistence mechanism — an attacker who can drive it installs an image that survives every subsequent remediation. Companion issue CVE-2018-6436 does the same through the firmwaredownload CLI command for a local attacker.

Who can reach it

Authenticated remote user with Webtools access on FOS before 8.2.1 / 8.1.2f / 8.0.2f / 7.4.2d.

What to do

Fabric OS upgrade plus reboot. Disable Webtools if your operations are CLI/REST-driven — a live config change. Verify installed firmware digests against Broadcom's published values after any suspicious period, because a patched switch running a tampered image is still compromised.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.