CVE-2018-6439
7.8 HIGHA Vulnerability in the configdownload command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7....
Published: 2018-12-03 · Last updated: 2026-06-03
Severity and scoring
- CVSS
- 7.8 HIGH
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
| Vendor | Product |
|---|---|
| broadcom | fabric_operating_system |
Description
A Vulnerability in the configdownload command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, gain root access.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2018-6439
- [Vendor advisory]https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2018-730
- [Vendor advisory]https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2018-730
Related CVEs
Same vendor
- CVE-2026-44839 — RabbitMQ is a messaging and streaming broker (4.8 MEDIUM)
- CVE-2026-44838 — RabbitMQ is a messaging and streaming broker (8.1 HIGH)
- CVE-2022-23305 — By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are conv... (9.8 CRITICAL)
- CVE-2022-23302 — JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j c... (8.8 HIGH)