CVE-2018-6433
MEDIUMBrocade Fabric OS < 7.4.2d - Unauthenticated File Copy Bypass via secryptocfg Export Command
Title source: llmDescription
A vulnerability in the secryptocfg export command of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to bypass the export file access restrictions and initiate a file copy from the source to a remote system.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2018-728
Scores
CVSS v3
5.5
EPSS
0.0005
EPSS Percentile
16.7%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-20
Status
published
Products (1)
broadcom/fabric_operating_system
7.4.2 - 7.4.2d
Published
Nov 08, 2018
Tracked Since
Feb 18, 2026