Vulnerabilities > CVE-2018-6443 - Credentials Management vulnerability in multiple products

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
high complexity
brocade
netapp
CWE-255
exploit available

Summary

A vulnerability in Brocade Network Advisor Versions before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentials and install additional JEE applications. A remote unauthenticated user who has access to Network Advisor client libraries and able to decrypt the Jboss credentials could gain access to the Jboss web console.

Common Weakness Enumeration (CWE)

Exploit-Db

idEDB-ID:46887
last seen2019-05-21
modified2019-05-21
published2019-05-21
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/46887
titleBrocade Network Advisor 14.4.1 - Unauthenticated Remote Code Execution

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/153035/brocadena1441-exec.txt
idPACKETSTORM:153035
last seen2019-05-24
published2019-05-23
reporterJakub Palaczynski
sourcehttps://packetstormsecurity.com/files/153035/Brocade-Network-Advisor-14.4.1-Unauthenticated-Remote-Code-Execution.html
titleBrocade Network Advisor 14.4.1 Unauthenticated Remote Code Execution