CVE-2018-6445
Estado: ModificadaAlta (7.5)—
A Vulnerability in Brocade Network Advisor versions before 14.0.3 could allow a remote unauthenticated attacker to export the current user database which includes the encrypted (not hashed) password of the systems. The attacker could gain access to the Brocade Network Advisor System after extracting/decrypting the passwords.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.67%
- Percentil entre todas las CVEs puntuadas: 76
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- NVD-CWE-noinfo
Referencias
- https://security.netapp.com/advisory/ntap-20190411-0005/
- https://support.lenovo.com/us/en/product_security/LEN-25655
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2018-745
- https://security.netapp.com/advisory/ntap-20190411-0005/
- https://support.lenovo.com/us/en/product_security/LEN-25655
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2018-745
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-6445",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "sirt@brocade.com",
"affectedData": [
{
"vendor": "Brocade Communications Systems, Inc.",
"product": "Brocade Network Advisor",
"versions": [
{
"status": "affected",
"version": "All versions prior to version 14.0.3"
}
]
}
]
}
],
"published": "2019-01-22T17:29:00.410",
"references": [
{
"url": "https://security.netapp.com/advisory/ntap-20190411-0005/",
"tags": [
"Third Party Advisory"
],
"source": "sirt@brocade.com"
},
{
"url": "https://support.lenovo.com/us/en/product_security/LEN-25655",
"source": "sirt@brocade.com"
},
{
"url": "https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2018-745",
"tags": [
"Vendor Advisory"
],
"source": "sirt@brocade.com"
},
{
"url": "https://security.netapp.com/advisory/ntap-20190411-0005/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.lenovo.com/us/en/product_security/LEN-25655",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2018-745",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A Vulnerability in Brocade Network Advisor versions before 14.0.3 could allow a remote unauthenticated attacker to export the current user database which includes the encrypted (not hashed) password of the systems. The attacker could gain access to the Brocade Network Advisor System after extracting/decrypting the passwords."
},
{
"lang": "es",
"value": "Una vulnerabilidad en Brocade Network Advisor, en versiones anteriores a la 14.0.3, podría permitir a un atacante remoto no autenticado exportar la base de datos del usuario actual que incluye las contraseñas cifradas (no hasheadas) de los sistemas. El atacante podría obtener acceso al sistema de Brocade Network Advisor después de extraer/descifrar las contraseñas."
}
],
"lastModified": "2026-06-17T02:01:50.773",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:brocade:network_advisor:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5295A4EC-6805-4D7D-B52E-087273B70595",
"versionEndExcluding": "14.0.3"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:netapp:brocade_network_advisor:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BFD0457F-30E5-4AD4-9281-8344CF2B009E"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "sirt@brocade.com"
}