Database/Firmware, BMC & network fabric
Brocade Fabric OS Webtools (firmware update section): A remote authenticated attacker can abuse the Webtools
Impact
A remote authenticated attacker can abuse the Webtools firmware-update path. Firmware update on a SAN switch is the persistence mechanism — an attacker who can drive it installs an image that survives every subsequent remediation. Companion issue CVE-2018-6436 does the same through the firmwaredownload CLI command for a local attacker.
Who can reach it
Authenticated remote user with Webtools access on FOS before 8.2.1 / 8.1.2f / 8.0.2f / 7.4.2d.
What to do
Fabric OS upgrade plus reboot. Disable Webtools if your operations are CLI/REST-driven — a live config change. Verify installed firmware digests against Broadcom's published values after any suspicious period, because a patched switch running a tampered image is still compromised.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.