GPU VulnDB

Database/Control plane, storage & DevOps

Brocade Fabric OS (proxy service information disclosure): Unauthenticated remote attackers can obtain sensitive

CVE-2018-6440Control plane, storage & DevOpscurated

Impact

Unauthenticated remote attackers can obtain sensitive information from the Fabric OS proxy service. Pre-auth information disclosure on a SAN switch typically yields fabric topology and configuration — which is the reconnaissance an attacker needs to know which zone to attack to reach a specific tenant's storage.

Who can reach it

Unauthenticated, remote to the FOS proxy service.

What to do

Fabric OS upgrade plus reboot per fabric. Immediate control is management-network isolation for all FC switch management interfaces.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.