vendor:
Brocade Network Advisor
by:
Jakub Palaczynski
8.1
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Brocade Network Advisor
Affected Version From: Brocade Network Advisor 14.X.X versions
Affected Version To: EMC Connectrix Manager Converged Network Edition 14.4.1
Patch Exists: YES
Related CWE: CVE-2018-6443
CPE: //a:broadcom:brocade_network_advisor
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows, Linux, Mac
2017
Brocade Network Advisor – Unauthenticated Remote Code Execution
Exploit uses hardcoded and undocumented credentials for JBoss JMX to execute arbitrary command on system.
Mitigation:
Ensure that all JMX credentials are properly secured and that access to the JMX port is restricted to trusted sources.