Database/Control plane, storage & DevOps
Brocade Fabric OS (proxy service information disclosure): Unauthenticated remote attackers can obtain sensitive
CVSS 9.1CVE-2018-6440Control plane, storage & DevOpscurated
Impact
Unauthenticated remote attackers can obtain sensitive information from the Fabric OS proxy service. Pre-auth information disclosure on a SAN switch typically yields fabric topology and configuration — which is the reconnaissance an attacker needs to know which zone to attack to reach a specific tenant's storage.
Who can reach it
Unauthenticated, remote to the FOS proxy service.
What to do
Fabric OS upgrade plus reboot per fabric. Immediate control is management-network isolation for all FC switch management interfaces.
References
Related entries
- IBM Spectrum Scale 5.1 core / IBM Elastic Storage System 6.1: Unauthorized access to user data, or injection ofCVE-2020-4926 · IBM Spectrum Scale 5.1 core / IBM Elastic Storage System 6.1Critical
- Cisco APIC / Cloud APIC (API endpoint): Unauthenticated arbitrary file read and write on the APICCVE-2021-1577 · Cisco APIC / Cloud APIC (API endpoint)Critical
- Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and prior: Path traversal to remote code executionCVE-2021-22794 · Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and priorCritical
- Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and prior: OS command injection over the networkCVE-2021-22795 · Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and priorCritical
- Ceph Manager (volumes plugin): Owner of one CephFS share can read/write any share or the entire file systemCVE-2022-0670 · Ceph Manager (volumes plugin)Critical
- Zabbix: Unverified user login in session data (SAML SSO enabled)CVE-2022-23131 · ZabbixCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.