Vulnerability Description
The QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 modules for IBM BladeCenter have an undocumented support account with a support password, an undocumented diags account with a diags password, and an undocumented prom account with a prom password.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Qlogic 4 Gb Fibre Channel Expansion Card Firmware | 5.5.2.6.0 |
| Ibm | Qlogic 4 Gb Fibre Channel Expansion Card | - |
| Ibm | Qlogic 20-Port 4\/8 Gb San Switch Module Firmware | 7.10.1.20.0 |
| Ibm | Qlogic 20-Port 4\/8 Gb San Switch Module | - |
References
- http://misteralfa-hack.blogspot.com/2018/10/ibm-bladecenter-qlogic-4g-fibre-chanExploitThird Party Advisory
- http://misteralfa-hack.blogspot.com/2018/10/ibm-bladecenter-qlogic-4g-fibre-chanExploitThird Party Advisory
FAQ
What is CVE-2018-18202?
CVE-2018-18202 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 modules for IBM BladeCenter have an undocumented support account with a support password, an undocumented diags account with a diags pa...
How severe is CVE-2018-18202?
CVE-2018-18202 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-18202?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Qlogic 4 Gb Fibre Channel Expansion Card Firmware, Ibm Qlogic 4 Gb Fibre Channel Expansion Card, Ibm Qlogic 20-Port 4\/8 Gb San Switch Module Firmware, Ibm Qlogic 20-Port 4\/8 Gb San Switch Module.