CVE-2018-6443
CVE-2018-6443 Vulnerability Analysis & Exploit Intelligence
A vulnerability in Brocade Network Advisor Versions before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentials and install additional JEE applications. A remote unauthenticated user who has access to Network Advisor client libraries and able to decrypt the Jboss credentials could gain access to the Jboss web console.
Published Updated Sources: cvelistV5, brocade
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Exploit code
public exploit, none observed
EPSS
7%
chance of exploitation in 30 days
CVSS base
Unscored
no source published a base score
Affected scope
The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.
Vendors (1)
Products (1)
Public exploit
Capability, not use: code existing is a different claim from anyone running it.
Indexed by
References
3 on the record
- www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2018-743
x_refsource_CONFIRM
- security.netapp.com/advisory/ntap-20190411-0005/
x_refsource_CONFIRM
- packetstormsecurity.com/files/153035/Brocade-Network-Advisor-14.4.1-Unauthenticated-Remote-Code-Execution.html
x_refsource_MISC
Elsewhere on this site
- brocade communications systemsevery CVE for this vendor
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.