{"api_version":"1","generated_at":"2026-04-23T02:57:51+00:00","cve":"CVE-2018-6445","urls":{"html":"https://cve.report/CVE-2018-6445","api":"https://cve.report/api/cve/CVE-2018-6445.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-6445","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-6445"},"summary":{"title":"CVE-2018-6445","description":"A Vulnerability in Brocade Network Advisor versions before 14.0.3 could allow a remote unauthenticated attacker to export the current user database which includes the encrypted (not hashed) password of the systems. The attacker could gain access to the Brocade Network Advisor System after extracting/decrypting the passwords.","state":"PUBLIC","assigner":"sirt@brocade.com","published_at":"2019-01-22 17:29:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2018-745","name":"https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2018-745","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Broadcom Inc. | Connecting Everything","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.lenovo.com/us/en/product_security/LEN-25655","name":"https://support.lenovo.com/us/en/product_security/LEN-25655","refsource":"CONFIRM","tags":[],"title":"Brocade Network Advisor Vulnerabilities - Lenovo Support US","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.netapp.com/advisory/ntap-20190411-0005/","name":"https://security.netapp.com/advisory/ntap-20190411-0005/","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"January 2019 Brocade Network Advisor Vulnerabilities in NetApp Products | NetApp Product Security","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-6445","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-6445","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"6445","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"brocade","cpe5":"network_advisor","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"6445","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"brocade","cpe5":"network_advisor","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"6445","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"netapp","cpe5":"brocade_network_advisor","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"6445","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"netapp","cpe5":"brocade_network_advisor","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"sirt@brocade.com","ID":"CVE-2018-6445","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Brocade Network Advisor","version":{"version_data":[{"version_value":"All versions prior to version 14.0.3"}]}}]},"vendor_name":"Brocade Communications Systems, Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A Vulnerability in Brocade Network Advisor versions before 14.0.3 could allow a remote unauthenticated attacker to export the current user database which includes the encrypted (not hashed) password of the systems. The attacker could gain access to the Brocade Network Advisor System after extracting/decrypting the passwords."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Improper Access Control"}]}]},"references":{"reference_data":[{"name":"https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2018-745","refsource":"CONFIRM","url":"https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2018-745"},{"refsource":"CONFIRM","name":"https://security.netapp.com/advisory/ntap-20190411-0005/","url":"https://security.netapp.com/advisory/ntap-20190411-0005/"},{"refsource":"CONFIRM","name":"https://support.lenovo.com/us/en/product_security/LEN-25655","url":"https://support.lenovo.com/us/en/product_security/LEN-25655"}]}},"nvd":{"publishedDate":"2019-01-22 17:29:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:brocade:network_advisor:*:*:*:*:*:*:*:*","versionEndExcluding":"14.0.3","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:netapp:brocade_network_advisor:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"6445","Ordinal":"122532","Title":"CVE-2018-6445","CVE":"CVE-2018-6445","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"6445","Ordinal":"1","NoteData":"A Vulnerability in Brocade Network Advisor versions before 14.0.3 could allow a remote unauthenticated attacker to export the current user database which includes the encrypted (not hashed) password of the systems. The attacker could gain access to the Brocade Network Advisor System after extracting/decrypting the passwords.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"6445","Ordinal":"2","NoteData":"2019-01-22","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"6445","Ordinal":"3","NoteData":"2019-06-18","Type":"Other","Title":"Modified"}]}}}