IBM Support

Security Bulletin: Brocade Fabric OS (FOS) Advisory vulnerabilities affect Brocade 8Gb SAN Switch Module for BladeCenter and IBM Flex System FC5022 16Gb SAN Scalable Switch

Security Bulletin


Summary

The following Brocade Fabric OS (FOS) vulnerabilities have been addressed by Brocade 8Gb SAN Switch Module for BladeCenter and IBM Flex System FC5022 16Gb SAN Scalable Switch.

Vulnerability Details

CVEID: CVE-2018-6442
DESCRIPTION: Broadcom Brocade Fabric OS could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by a flaw in the Brocade Webtools firmware update section. By sending specially-crafted arguments, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVSS Base Score: 8.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/152758 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

CVEID: CVE-2018-6441
DESCRIPTION: Broadcom Brocade Fabric OS could allow a local attacker to bypass security restrictions, caused by a flaw in the Secure Shell implementation. By sending a specially-crafted argument, an attacker could exploit this vulnerability to provide arbitrary environment variables and bypass the restricted configuration shell.
CVSS Base Score: 4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/152757 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

CVEID: CVE-2018-6440
DESCRIPTION: Broadcom Brocade Fabric OS could allow a remote attacker to obtain sensitive information, caused by a flaw in the proxy service. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to obtain sensitive information or cause a denial of service condition.
CVSS Base Score: 7.2
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/152909 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L)

CVEID: CVE-2018-6439
DESCRIPTION: Broadcom Fabric OS could allow a local attacker to bypass security restrictions, caused by a flaw in the configdownload command in the command line interface. By sending a specially-crafted request, an attacker could exploit this vulnerability to escape the restricted shell and gain root access.
CVSS Base Score: 6.2
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/153836 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)

CVEID: CVE-2018-6438
DESCRIPTION: Broadcom Brocade Fabric OS could allow a local attacker to gain elevated privileges on the system, caused by a flaw in the supportsave command by the command line interface (CLI). By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain root shell access.
CVSS Base Score: 8.4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/152800 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID: CVE-2018-6437
DESCRIPTION: Broadcom Brocade Fabric OS could allow a local attacker to gain elevated privileges on the system, caused by a flaw in the help command by the command line interface (CLI). By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain root shell access.
CVSS Base Score: 8.4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/152799 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID: CVE-2018-6436
DESCRIPTION: Broadcom Brocade Fabric OS could allow a local attacker to gain elevated privileges on the system, caused by a flaw in the firmwaredownload command by the command line interface (CLI). By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain root shell access.
CVSS Base Score: 8.4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/152798 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID: CVE-2018-6435
DESCRIPTION: Broadcom Brocade Fabric OS could allow a local attacker to gain elevated privileges on the system, caused by a flaw in the secryptocfg command. By sending specially-crafted arguments, an attacker could exploit this vulnerability to escape the restricted shell and gain root access.
CVSS Base Score: 8.4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/152756 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID: CVE-2018-6434
DESCRIPTION: Broadcom Brocade Fabric OS could could allow a remote attacker to hijack a user''s session. By persuading a victim to click on a specially-crafted Web site, an attacker could exploit this vulnerability using the web management interface to gain access to another user''s session.
CVSS Base Score: 6.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/152755 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)

CVEID: CVE-2018-6433
DESCRIPTION: Broadcom Brocade Fabric OS could allow a local attacker to bypass security restrictions, caused by a flaw in the ecryptocfg export command. By sending a specially-crafted argument, an attacker could exploit this vulnerability to perform arbitrary file copy from source to a remote system.
CVSS Base Score: 4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/152752 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Product

Affected Version

IBM Flex System FC5022 16Gb SAN Scalable Switch Firmware
8.0
Fabric OS firmware for Brocade 8Gb SAN  Switch Module
7.4

Remediation/Fixes

Product

Fixed Version

IBM Flex System FC5022 16Gb SAN Scalable Switch Firmware
(brcd_fw_bcsw_8.2.1_anyos_noarch)
8.2.1
Fabric OS firmware for Brocade 8Gb SAN  Switch Module
(brcd_fw_bcsw_7.4.2d_anyos_noarch)
7.4.2d

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Change History

21 June 2019: Initial version published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Document Location

Worldwide

[{"Business Unit":{"code":"BU050","label":"BU NOT IDENTIFIED"},"Product":{"code":"SSWLYD","label":"PureFlex System \u0026 Flex System"},"Component":"Machine Types: 8721,8724,7893","Platform":[{"code":"PF009","label":"Firmware"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"","label":""}},{"Type":"HW","Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"HW21Y","label":"BladeCenter H Chassis"},"Platform":[{"code":"PF009","label":"Firmware"}],"Line of Business":{"code":"LOB57","label":"Power"}}]

Document Information

Modified date:
21 June 2019

UID

ibm10888177