CVE-2020-15372
https://notcve.org/view.php?id=CVE-2020-15372
A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2.2a1, 8.2.2c, v7.4.2g, v8.2.0_CBN3, v8.2.1e, v8.1.2k, v9.0.0, could allow a local authenticated attacker to modify shell variables, which may lead to an escalation of privileges or bypassing the logging. Una vulnerabilidad en la interfaz de línea de comandos en Brocade Fabric OS antes de Brocade Fabric OS versiones v8.2.2a1, 8.2.2c, v7.4.2g, v8.2.0_CBN3, v8.2.1e, v8.1.2k, v9.0.0, podría permitir a un atacante autenticado local modificar las variables de shell, lo que puede conllevar a una escalada de privilegios o una omisión del registro • https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2020-1081 • CWE-913: Improper Control of Dynamically-Managed Code Resources •
CVE-2020-15370
https://notcve.org/view.php?id=CVE-2020-15370
Brocade Fabric OS versions before Brocade Fabric OS v7.4.2g could allow an authenticated, remote attacker to view a user password in cleartext. The vulnerability is due to incorrectly logging the user password in log files. Brocade Fabric OS versiones anteriores a Brocade Fabric OS v7.4.2g, podían permitir a un atacante remoto autenticado visualizar una contraseña de usuario en texto sin cifrar. La vulnerabilidad es debido al registro incorrecto de la contraseña de usuario en los archivos de registro • https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2020-1079 • CWE-532: Insertion of Sensitive Information into Log File •
CVE-2018-6448
https://notcve.org/view.php?id=CVE-2018-6448
A vulnerability in the management interface in Brocade Fabric OS Versions before Brocade Fabric OS v9.0.0 could allow a remote attacker to perform a denial of service attack on the vulnerable host. Una vulnerabilidad en la interfaz de administración en Brocade Fabric OS versiones anteriores a Brocade Fabric OS v9.0.0, podría permitir a un atacante remoto llevar a cabo un ataque de denegación de servicio en el host vulnerable • https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2020-1075 •
CVE-2018-6449
https://notcve.org/view.php?id=CVE-2018-6449
Host Header Injection vulnerability in the http management interface in Brocade Fabric OS versions before v9.0.0 could allow a remote attacker to exploit this vulnerability by injecting arbitrary HTTP headers Una vulnerabilidad de inyección de encabezado de host en la interfaz de administración http en Brocade Fabric OS versiones anteriores a v9.0.0, podría permitir a un atacante remoto explotar esta vulnerabilidad mediante la inyección de encabezados HTTP arbitrarios • https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2020-1077 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-6447
https://notcve.org/view.php?id=CVE-2018-6447
A Reflective XSS Vulnerability in HTTP Management Interface in Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g could allow authenticated attackers with access to the web interface to hijack a user’s session and take over the account. Una vulnerabilidad de tipo XSS Reflexivo en la Interfaz de Administración HTTP en Brocade Fabric OS versiones anteriores a Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g, podría permitir a atacantes autenticados con acceso a la interfaz web secuestrar la sesión de un usuario y tomar el control de la cuenta • https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2020-1073 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •