Database/Control plane, storage & DevOps
Brocade Fabric OS (proxy service information disclosure): Unauthenticated remote attackers can obtain sensitive
CVE-2018-6440Control plane, storage & DevOpscurated
Impact
Unauthenticated remote attackers can obtain sensitive information from the Fabric OS proxy service. Pre-auth information disclosure on a SAN switch typically yields fabric topology and configuration — which is the reconnaissance an attacker needs to know which zone to attack to reach a specific tenant's storage.
Who can reach it
Unauthenticated, remote to the FOS proxy service.
What to do
Fabric OS upgrade plus reboot per fabric. Immediate control is management-network isolation for all FC switch management interfaces.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.