Database/Firmware, BMC & network fabric
Brocade Fabric OS Webtools (firmware update section): A remote authenticated attacker can abuse the Webtools
Impact
A remote authenticated attacker can abuse the Webtools firmware-update path. Firmware update on a SAN switch is the persistence mechanism — an attacker who can drive it installs an image that survives every subsequent remediation. Companion issue CVE-2018-6436 does the same through the firmwaredownload CLI command for a local attacker.
Who can reach it
Authenticated remote user with Webtools access on FOS before 8.2.1 / 8.1.2f / 8.0.2f / 7.4.2d.
What to do
Fabric OS upgrade plus reboot. Disable Webtools if your operations are CLI/REST-driven — a live config change. Verify installed firmware digests against Broadcom's published values after any suspicious period, because a patched switch running a tampered image is still compromised.
References
Related entries
- Eaton UPS 9PX 8000 SP administration panel: CSRF on the change-password function plus reflected XSS: an attacker forcesCVE-2018-9281 · Eaton UPS 9PX 8000 SP administration panelHigh
- Intel Ethernet 700 Series Controller firmware (X710/XL710/XXV710): Buffer overflow in the adapter firmware of Intel'sCVE-2019-0140 · Intel Ethernet 700 Series Controller firmware (X710/XL710/XXV710)High
- Intel CSME / TXE: A heap overflow in a CSME subsystem reachable by an unauthenticated attacker for privilege escalationCVE-2019-0169 · Intel CSME / TXEHigh
- Supermicro BMC virtual media subsystem on X8STi-F with IPMI firmware 2.06: The researcher's own descriptionCVE-2019-19642 · Supermicro BMC virtual media subsystem on X8STi-F with IPMI firmware 2.06High
- NVIDIA DGX BMC (AMI firmware): CSRF in the BMC web applicationCVE-2020-11485 · NVIDIA DGX BMC (AMI firmware)High
- Rittal PDU-3C002DEC rack PDU firmware (through 5.15.40): Arbitrary code execution on the rack PDUCVE-2020-11953 · Rittal PDU-3C002DEC rack PDU firmware (through 5.15.40)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.