First published: Tue Jan 22 2019(Updated: )
A Vulnerability in Brocade Network Advisor versions before 14.0.3 could allow a remote unauthenticated attacker to export the current user database which includes the encrypted (not hashed) password of the systems. The attacker could gain access to the Brocade Network Advisor System after extracting/decrypting the passwords.
Credit: sirt@brocade.com
Affected Software | Affected Version | How to fix |
---|---|---|
Brocade Network Advisor | <14.0.3 | |
Netapp Brocade Network Advisor |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-6445.
The title of the vulnerability is 'A Vulnerability in Brocade Network Advisor versions before 14.0.3 could allow a remote unauthenticated attacker to export the current user database which includes the encrypted (not hashed) password of the systems.'
The severity of CVE-2018-6445 is high with a severity value of 7.5.
Brocade Network Advisor versions before 14.0.3 and Netapp Brocade Network Advisor are affected by CVE-2018-6445.
An attacker can exploit CVE-2018-6445 by remotely accessing the Brocade Network Advisor System and extracting the user database, which includes encrypted passwords.