CVE-2018-18202: IBM Qlogic 20-Port 4/8 Gb San Switch Module Firmware

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

The QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 modules for IBM BladeCenter have an undocumented support account with a support password, an undocumented diags account with a diags password, and an undocumented prom account with a prom password.

Affected products

  • IBM Qlogic 20-Port 4/8 Gb San Switch Module Firmware: version 7.10.1.20.0 only
  • IBM Qlogic 4 Gb Fibre Channel Expansion Card Firmware: version 5.5.2.6.0 only

Published 2018-10-10. Last modified 2026-06-17.