PT-2020-14396 · Brocade · Brocade Fabric Os

Published

2020-09-25

·

Updated

2021-08-23

·

CVE-2020-15369

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Brocade Fabric OS versions 8.2.1 through 8.2.1d Brocade Fabric OS versions 8.2.2 before 8.2.2c
Description The issue is related to the Supportlink CLI in Brocade Fabric OS, where it does not obfuscate the password field. This could expose users' credentials of the remote server, allowing an authenticated user to obtain the exposed password credentials and gain access to the remote host.
Recommendations For Brocade Fabric OS versions 8.2.1 through 8.2.1d, consider disabling the Supportlink CLI until a patch is available to prevent exposure of password credentials. For Brocade Fabric OS versions 8.2.2 before 8.2.2c, consider disabling the Supportlink CLI until a patch is available to prevent exposure of password credentials.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15369

Affected Products

Brocade Fabric Os