PT-2022-21729 · Brocade · Brocade Sannav

Published

2022-12-09

·

Updated

2022-12-12

·

CVE-2022-33187

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Brocade SANnav versions prior to 2.2.1
Description The issue allows an attacker with admin privilege to read sensitive information, including usernames and encoded passwords, which are logged in debug-enabled logs.
Recommendations For versions prior to 2.2.1, update to version 2.2.1 or later to resolve the issue. As a temporary workaround, consider disabling debug logging until a patch is available. Restrict access to debug logs to minimize the risk of exploitation.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2022-33187

Affected Products

Brocade Sannav