PT-2020-14396 · Brocade · Brocade Fabric Os
Published
2020-09-25
·
Updated
2021-08-23
·
CVE-2020-15369
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Brocade Fabric OS versions 8.2.1 through 8.2.1d
Brocade Fabric OS versions 8.2.2 before 8.2.2c
Description
The issue is related to the Supportlink CLI in Brocade Fabric OS, where it does not obfuscate the password field. This could expose users' credentials of the remote server, allowing an authenticated user to obtain the exposed password credentials and gain access to the remote host.
Recommendations
For Brocade Fabric OS versions 8.2.1 through 8.2.1d, consider disabling the Supportlink CLI until a patch is available to prevent exposure of password credentials.
For Brocade Fabric OS versions 8.2.2 before 8.2.2c, consider disabling the Supportlink CLI until a patch is available to prevent exposure of password credentials.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Brocade Fabric Os